Router threat detection method and device and electronic equipment

By generating a target feature matrix and dynamically adjusting parameters, the threat detection model solves the problem of insufficient detection by routing devices when facing complex network attacks, and achieves higher accuracy and real-time threat detection.

CN120811705APending Publication Date: 2025-10-17CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511071732.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

In existing technologies, when routing devices face complex and diverse network attacks, traditional security protection methods such as firewall technology cannot effectively detect them, resulting in insufficient detection accuracy and real-time performance.

Method used

By calculating real-time network traffic data from routing devices, a target feature matrix is ​​generated, including features such as burst traffic intensity index, short connection ratio, DNS query anomaly rate, and TLS handshake failure rate. The parameters of the threat detection model are dynamically adjusted to form a target threat detection model to detect abnormal traffic.

Benefits of technology

It improves the accuracy and adaptability of threat detection for routing devices, enabling them to better adapt to changes in traffic characteristics and significantly enhance detection accuracy and real-time performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811705A_ABST
    Figure CN120811705A_ABST
Patent Text Reader

Abstract

The invention discloses a router threat detection method, a router threat detection device and electronic equipment, relates to the technical field of network security, and is used for improving the anomaly detection accuracy of routing equipment. The method comprises the following steps: firstly, calculating a target feature matrix based on N pieces of real-time network flow data; then, calculating a dynamic adjustment parameter based on the target feature matrix, and performing parameter adjustment on the initial threat detection model according to the dynamic adjustment parameter to obtain a target threat detection model; and finally, detecting whether the N pieces of real-time network flow data are abnormal or not by adopting the target threat detection model. According to the method, four types of unique flow characteristics are adopted, whether the current routing equipment is abnormal or not can be obviously reflected, and the accuracy of detecting the threat of the routing equipment is improved. Besides, the dynamic adjustment parameters of the model are dynamically adjusted, so that the model can better adapt to the change of the traffic characteristics of the routing equipment, and the accuracy and adaptability of the threat detection of the routing equipment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to a router threat detection method and device and electronic equipment. BACKGROUND

[0002] With the development of communication technology, routing devices have been deeply applied to our daily life. As the "traffic hub" of network communication, routing devices can be widely used in core tasks such as data forwarding, path selection, and traffic management. Whether it is the interconnection of intelligent devices in a home network or large-scale data transmission on the Internet, the stable operation of routing devices is indispensable.

[0003] However, with the popularity of routing devices, new security challenges have also arisen. Various network attack methods are becoming increasingly complex and diverse. Routing devices have become the focus of attackers. Once the routing device is compromised, the attacker can not only obtain sensitive information transmitted in the network, but also control the flow direction of the entire network by tampering with the routing configuration, causing network paralysis, service termination, and other problems.

[0004] In related technologies, traditional security protection methods, such as firewall technology and intrusion detection systems, usually only perform threat detection based on set rules, which have the problem of rule update lag, and cannot effectively face new attacks, making it difficult to cope with the diversity and complexity of routing device attacks. SUMMARY

[0005] The embodiments of the present application provide a router threat detection method, device and electronic equipment, which can solve the problem that the existing technology such as firewall technology can only perform threat detection based on set rules and cannot face the diversity and complexity of new attack methods. The accuracy and real-time performance of router threat detection can be significantly improved.

[0006] In a first aspect, the present application provides a router threat detection method, comprising:

[0007] Based on N pieces of real-time network traffic data, a target feature matrix is calculated; wherein the target feature matrix at least includes: burst traffic intensity index, representing the fluctuation degree of traffic data of the routing device within a preset time period, short connection proportion, representing the proportion of short connection times in the total connection times, DNS query abnormal rate, representing the proportion of abnormal DNS query times in the total DNS query times, TLS handshake failure rate, representing the proportion of TLS handshake failure times in the total TLS handshake times;

[0008] The dynamic adjustment parameter is calculated based on the target feature matrix, and the initial threat detection model is adjusted in parameters according to the dynamic adjustment parameter, to obtain a target threat detection model; wherein the dynamic adjustment parameter is used to limit the regularization degree and complexity of the target threat detection model.

[0009] The target threat detection model is used to detect whether there is an anomaly in the N pieces of real-time network traffic data.

[0010] Through the above method, four unique traffic features are used to significantly reflect whether the current routing device has an anomaly, thereby improving the accuracy of routing device threat detection. In addition, the dynamic adjustment parameter of the model can be dynamically adjusted to better adapt to the changes in the traffic features of the routing device, thereby improving the accuracy and adaptability of routing device threat detection.

[0011] In an optional implementation, the target feature matrix is calculated based on the N pieces of real-time network traffic data, comprising:

[0012] The maximum packet size, average packet size, short connection times, total connection times, TLS handshake failure times, TLS handshake total times, abnormal DNS query times, and DNS query total times corresponding to the N pieces of real-time network traffic data are obtained.

[0013] The burst traffic intensity index is calculated according to the maximum packet size and the average packet size.

[0014] The short connection proportion is calculated according to the short connection times and the total connection times.

[0015] The TLS handshake failure rate is calculated according to the TLS handshake failure times and the TLS handshake total times.

[0016] The DNS query anomaly rate is calculated according to the abnormal DNS query times and the DNS query total times.

[0017] The target feature matrix is obtained based on the burst traffic intensity index, the short connection proportion, the TLS handshake failure rate, and the DNS query anomaly rate.

[0018] Through the above method, the four unique features are used to accurately distinguish between normal traffic and abnormal traffic, thereby improving the accuracy of routing device threat detection.

[0019] In an optional implementation, the dynamic adjustment parameter is calculated based on the target feature matrix, and the initial threat detection model is adjusted in parameters according to the dynamic adjustment parameter, to obtain a target threat detection model, comprising:

[0020] obtaining a first dynamic adjustment parameter, a second dynamic adjustment parameter, a third dynamic adjustment parameter, a target feature matrix, and a weight parameter set corresponding to the target feature matrix; wherein the first dynamic adjustment parameter is a dynamic adjustment parameter currently used by the initial threat detection model, the second dynamic adjustment parameter is used to indicate an upper limit value of the dynamic adjustment parameter, the third dynamic adjustment parameter is used to indicate a lower limit value of the dynamic adjustment parameter, and each weight parameter in the weight parameter set corresponds to a target feature in the target feature matrix;

[0021] According to the first dynamic adjustment parameter, the second dynamic adjustment parameter, the third dynamic adjustment parameter, the target feature matrix, and the weight parameter set corresponding to the target feature matrix, a dynamic adjustment parameter is calculated;

[0022] According to the dynamic adjustment parameter, the initial threat detection model is adjusted to obtain a target threat detection model.

[0023] Through the above method, the regularization parameter is dynamically adjusted, which can make the model better adapt to the change of the traffic characteristics of the routing device, thereby improving the detection accuracy.

[0024] In an optional implementation, N pieces of real-time network traffic data are detected by using the target threat detection model to determine whether there is an anomaly, comprising:

[0025] The target feature matrix is input into the target threat detection model;

[0026] According to the detection result output by the target threat detection model, it is determined whether the N pieces of real-time network traffic data have an anomaly.

[0027] In a second aspect, the application provides a router threat detection device, comprising:

[0028] The computing module is configured to calculate a target feature matrix based on N pieces of real-time network traffic data; wherein the target feature matrix at least includes: burst traffic intensity index, representing the fluctuation degree of traffic data of the routing device within a preset time period, short connection proportion, representing the proportion of short connection times in total connection times, DNS query anomaly rate, representing the proportion of abnormal DNS query times in total DNS query times, TLS handshake failure rate, representing the proportion of TLS handshake failure times in total TLS handshake times;

[0029] The adjusting module is configured to calculate a dynamic adjustment parameter based on the target feature matrix, and to adjust the initial threat detection model based on the dynamic adjustment parameter to obtain a target threat detection model; wherein the dynamic adjustment parameter is used to limit the regularization degree and complexity of the target threat detection model;

[0030] The detection module detects whether N pieces of real-time network traffic data have an anomaly by using the target threat detection model.

[0031] In an optional implementation, when the target feature matrix is calculated based on the N pieces of real-time network traffic data, the calculation module is specifically configured to:

[0032] obtain the maximum packet size, the average packet size, the number of short connections, the total number of connections, the number of TLS handshake failures, the total number of TLS handshakes, the number of abnormal DNS queries, and the total number of DNS queries corresponding to the N pieces of real-time network traffic data;

[0033] calculate the burst traffic intensity index according to the maximum packet size and the average packet size;

[0034] calculate the short connection proportion according to the number of short connections and the total number of connections;

[0035] calculate the TLS handshake failure rate according to the number of TLS handshake failures and the total number of TLS handshakes;

[0036] calculate the DNS query anomaly rate according to the number of abnormal DNS queries and the total number of DNS queries;

[0037] obtain the target feature matrix based on the burst traffic intensity index, the short connection proportion, the TLS handshake failure rate, and the DNS query anomaly rate.

[0038] In an optional implementation, when the target threat detection model is obtained by calculating the dynamic adjustment parameter based on the target feature matrix and adjusting the parameters of the initial threat detection model according to the dynamic adjustment parameter, the adjustment module is specifically configured to:

[0039] obtain the first dynamic adjustment parameter, the second dynamic adjustment parameter, the third dynamic adjustment parameter, the target feature matrix, and a weight parameter set corresponding to the target feature matrix; wherein the first dynamic adjustment parameter is a dynamic adjustment parameter currently used by the initial threat detection model, the second dynamic adjustment parameter is used to indicate an upper limit value of the dynamic adjustment parameter, the third dynamic adjustment parameter is used to indicate a lower limit value of the dynamic adjustment parameter, and each weight parameter in the weight parameter set corresponds to a target feature in the target feature matrix;

[0040] calculate the dynamic adjustment parameter according to the first dynamic adjustment parameter, the second dynamic adjustment parameter, the third dynamic adjustment parameter, the target feature matrix, and the weight parameter set corresponding to the target feature matrix;

[0041] adjust the parameters of the initial threat detection model according to the dynamic adjustment parameter to obtain the target threat detection model.

[0042] In an optional implementation, when the target threat detection model is adopted to detect whether the N pieces of real-time network traffic data are abnormal, the detection module is specifically configured to:

[0043] inputting the target feature matrix into a target threat detection model;

[0044] determining whether the N pieces of real-time network traffic data are abnormal according to a detection result output by the target threat detection model.

[0045] In a third aspect, the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores program code, and when the program code is executed by the processor, the processor executes the steps of the router threat detection method in the first aspect.

[0046] In a fourth aspect, the present application provides a computer-readable storage medium comprising program code, and when the program code is run on an electronic device, the program code is used to make the electronic device execute the steps of the router threat detection method in the first aspect.

[0047] In a fifth aspect, the present application provides a computer program product, which, when invoked by a computer, makes the computer execute the steps of the router threat detection method in the first aspect.

[0048] In addition, other features and advantages of the present application will be described in the following description, and some will become apparent from the description, or will be understood through implementation of the present application. The purpose and other advantages of the present application can be achieved and obtained by the structure specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF DRAWINGS

[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor. In the drawings:

[0050] Figure 1 An application scenario schematic diagram of a router threat detection method provided by the embodiments of the present application;

[0051] Figure 2 An implementation flow schematic diagram of a router threat detection method provided by the embodiments of the present application;

[0052] Figure 3 A structure schematic diagram of a router threat detection device provided by the embodiments of the present application;

[0053] Figure 4 A structure schematic diagram of an electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION

[0054] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments described in the present application document, all other embodiments obtained by a person of ordinary skill in the art without creative labor fall within the scope of protection of the present application technical solutions.

[0055] It should be noted that in the description of the present application, "multiple" is understood as "at least two". The association relationship of "and / or" describing the associated objects means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. A and B are connected, which means that A and B are directly connected and A and B are connected through C. In addition, in the description of the present application, "first", "second", and the like are only used for the purpose of distinguishing the description, and cannot be understood as indicating or implying relative importance, nor can it be understood as indicating or implying order.

[0056] In addition, in the technical solutions of the present application, the collection, transmission, use, etc. of data all comply with the requirements of relevant national laws and regulations.

[0057] The design idea of the embodiments of the present application will be briefly introduced below:

[0058] With the development of communication technology, routing devices have been deeply applied to our daily life. As the "traffic hub" of network communication, routers can be widely used for core tasks such as data forwarding, path selection, and traffic management. Whether it is the interconnection of intelligent devices in a home network or large-scale data transmission on the Internet, the stable operation of routing devices is indispensable.

[0059] However, with the popularization of routing devices, new security challenges have also arisen. Various network attack methods are becoming increasingly complex and diversified. Routing devices have become the focus of attackers. Once the routing device is broken, the attacker can not only obtain sensitive information transmitted in the network, but also control the flow direction of the entire network by tampering with the routing configuration, causing network paralysis, service terminal, and other problems.

[0060] In related technologies, traditional security protection methods, such as firewall technology and intrusion detection systems, usually only perform threat detection based on set rules, which all have the problem of rule update lag, and cannot effectively face information attacks, making it difficult to cope with the diversity and complexity of routing device attacks.

[0061] Therefore, the application provides a router threat detection method, which comprises the following steps: firstly, calculating a target feature matrix based on N pieces of real-time traffic data; wherein the target feature matrix at least comprises a burst traffic intensity index, a short connection proportion, a DNS query abnormality rate, and a TLS handshake failure rate; the burst traffic intensity index represents the fluctuation degree of traffic data of a routing device within a preset time period; the short connection proportion represents the proportion of the number of short connections in the total number of connections; the DNS query abnormality rate represents the proportion of the number of abnormal DNS queries in the total number of DNS queries; and the TLS handshake failure rate represents the proportion of the number of TLS handshake failures in the total number of TLS handshakes; then, calculating a dynamic adjustment parameter based on the target feature matrix, and adjusting parameters of an initial threat detection model according to the dynamic adjustment parameter to obtain a target threat detection model; wherein the dynamic adjustment parameter is used to limit the regularization degree complexity of the target threat detection model; and finally, detecting whether the N pieces of real-time network traffic data are abnormal by using the target threat detection model. Through the above method, four unique traffic features are used, which can significantly reflect whether the current routing device is abnormal, and the accuracy of routing device threat detection is improved. In addition, the dynamic adjustment parameter of the model is dynamically adjusted, which can make the model better adapt to the changes of the traffic features of the routing device, thereby improving the accuracy and adaptability of the routing device threat detection.

[0062] In order to better understand the embodiments of the application, the technical terms involved in the embodiments of the application are first described below.

[0063] (1) The deep support vector data description model (Support Vector Description, SVDD) is a single-class classification model based on statistical learning, which is mainly used in fields such as anomaly detection and fault diagnosis. The core idea is to describe the data distribution by constructing a minimum volume hyper-sphere containing most of the normal data points, and then to distinguish normal data from abnormal data.

[0064] (2) The man-in-the-middle attack (Man-in-the-Middle Attack, MITM) is an “indirect” intrusion attack. This attack mode is to virtually place a computer controlled by an intruder between two communicating computers in a network connection, which is called “man-in-the-middle”. Through the “man-in-the-middle”, normal network communication data can be intercepted, data tampering or sniffing can be performed, and the two parties of the communication are unaware of it.

[0065] (3) The dynamic adjustment parameter λ of SVDD: is a key parameter in the SVDD model that controls the regularization strength. Its role is to balance the fitting target and the generalization ability by limiting the model complexity, so as to optimize the shape of the hyper-sphere and the anomaly detection effect.

[0066] (4) Adam (Adaptive Moment Estimation) optimizer: one of the commonly used optimization algorithms in deep learning, combining the advantages of momentum method and RMSProp, which can significantly improve the efficiency of model training by adaptively adjusting the learning rate.

[0067] (5) TLS (Transport Layer Security) handshake: used to create a secure connection between two applications through the network, preventing eavesdropping and tampering when exchanging data, involving key exchange, authentication, and other processes.

[0068] (7) Short connection: refers to establishing a connection only when data needs to be sent during data transmission, and disconnecting the connection after data transmission is completed, i.e., each connection only completes the transmission of one service.

[0069] The following will introduce the application scenarios of the technical solutions of the embodiments of the present application. It should be noted that the application scenarios introduced below are only used to illustrate the embodiments of the present application and are not limited. In specific implementation, the technical solutions provided by the embodiments of the present application can be flexibly applied according to actual needs.

[0070] Referring to FIG. 1, Figure 1 As shown in FIG. 1, it is a system architecture diagram provided by an embodiment of the present application, which includes a routing device 101, a target terminal 102 and a server 103. The target terminal 102 and the server 103 can interact with the routing device 101 through a communication network, wherein the communication network can adopt a communication mode including a wireless communication mode and a wired communication mode.

[0071] For example, the target terminal 102 and the server 103 can access the network through cellular mobile communication technology and communicate with the routing device 101, wherein the cellular mobile communication technology includes, for example, the 5th Generation Mobile Networks (5G) technology.

[0072] Optionally, the target terminal 102 and the server 103 can access the network through a short-range wireless communication mode and communicate with the routing device 103, wherein the short-range wireless communication mode includes, for example, the Wireless Fidelity (Wi-Fi) technology.

[0073] The embodiments of the present application do not make any limitation on the number of communication devices involved in the above system architecture, for example, there can be more target terminals, or no target terminal, or other network devices, such as Figure 1As shown, only the routing device 101, the target terminal 102 and the server 103 are taken as examples for description, and the above devices and their respective functions are briefly introduced as follows.

[0074] The routing device 101 is a hardware device connecting two or more networks, which acts as a gateway between networks, and is a special intelligent network device for reading the address in each data packet and then deciding how to transmit.

[0075] The target terminal 102 is a device that can provide voice and / or data connectivity to a user, which can be a device supporting wired and / or wireless connection mode.

[0076] For example, the target terminal 102 includes but is not limited to a mobile phone, a tablet computer, a notebook computer, a palm computer, a mobile Internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal device in industrial control, a wireless terminal device in unmanned driving, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, or a wireless terminal device in smart home, etc.

[0077] In addition, the target terminal 102 can be installed with a related client, and the client can be software such as an application (APP), a browser, a short video software, etc., or a webpage, an applet, etc.

[0078] The server 103 can be a standalone physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and basic cloud computing services such as big data and artificial intelligence platforms.

[0079] It is worth mentioning that in the embodiment of the present application, the server 103 can be used to obtain N pieces of real-time network traffic data collected by the routing device, and calculate a target feature matrix based on the N pieces of real-time network traffic data; wherein the target feature matrix at least includes: burst traffic intensity index, representing the fluctuation degree of traffic data of the routing device in a preset time period, short connection proportion, representing the proportion of short connection times in the total connection times, DNS query abnormal rate, representing the proportion of abnormal DNS query times in the total DNS query times, TLS handshake failure rate, representing the proportion of TLS handshake failures; then, a dynamic adjustment parameter is calculated based on the target feature matrix, and the initial threat detection model is adjusted in parameters according to the dynamic adjustment parameter to obtain a target threat detection model; wherein the dynamic adjustment parameter is used to limit the complexity of the target threat detection model; finally, the target threat detection model is used to detect whether the N pieces of real-time network traffic data are abnormal.

[0080] The router threat detection method provided by the example embodiment of the present application will be described below in combination with the above system architecture and with reference to the accompanying drawings. It should be noted that the above system architecture is only shown for the purpose of facilitating understanding of the spirit and principles of the present application, and the embodiments of the present application are not limited in this respect.

[0081] Referring to Figure 2 As shown in FIG. 8, which is an implementation flowchart of a router threat detection method provided by an embodiment of the present application, the execution subject is taken as an example of a server, and the specific implementation process of the method is as follows:

[0082] S1: calculating a target feature matrix based on N pieces of real-time network traffic data.

[0083] In the embodiment of the present application, first, N pieces of real-time network traffic data are obtained in a preset time period. N is a positive integer greater than or equal to 1. For example, the data packet capture technology (Data Plane Development Kit, DPDK) can be used to obtain N pieces of real-time network traffic data in a preset time period. A splitter can also be used to physically copy the network traffic data on the routing device to achieve lossless access and analysis of the routing device. Of course, other ways can also be used to obtain real-time network traffic data of the routing device, which is not limited in the present application, and the above is only for illustration.

[0084] For example, a total of 5 pieces of real-time network traffic data are collected in the preset time period of 8:00:00-8:00:50 by the above method, including protocol type, packet size, TLS handshake state, DNS query times, duration, etc. Referring to Table 1, which is a schematic table of N pieces of real-time network traffic data in a preset time period provided by an embodiment of the present application.

[0085] Table 1

[0086]

[0087]

[0088] Then, based on the N pieces of real-time network traffic data collected in the preset time period, representative unique features can be extracted, which can be represented by a feature matrix.

[0089] Specifically, in the embodiments of the present application, the target matrix at least includes: burst traffic intensity index (BI), short-lived connection ratio (SCR), DNS query anomaly rate (DQAR), and TLS handshake failure rate (THFR).

[0090] The burst traffic intensity index represents the fluctuation degree of data traffic of the routing device in the preset time period. If BI is too high, it means that the data traffic exceeds the link carrying capacity, which can cause packet loss or delay. If BI is continuously too high in a period of time, it means that there may be malicious traffic injection or network configuration errors. For example, the reference value of BI is 1, and the current BI is 5. Obviously, the current data traffic fluctuation degree is large, and the routing device is likely to be under attack. Therefore, BI can be used to effectively detect threats to the routing device.

[0091] The short connection ratio represents the proportion of the number of short connections in the total number of connections. If SCR is too high, it means that there may be malicious scanning. For example, an attacker quickly sends SYN packets to different IP ports to detect live hosts or vulnerabilities, and disconnects after receiving a response to evade firewall detection. In normal business, the proportion of short connections is usually low. Therefore, SCR can also be used to determine whether the routing device is under attack.

[0092] The DNS query anomaly rate represents the proportion of the number of DNS queries in the total number of DNS queries in the preset time period. The DNS query anomaly rate can identify abnormal DNS query situations. For example, random subdomain name query, which queries meaningless strings at a high frequency, and super-long domain name, which queries domain names with excessive length, resulting in excessive DNS query times. NXDOMAIN error means that there is no corresponding record in the DNS server when querying the domain name, resulting in excessive DNS query times. High DNS query anomaly rate can also significantly reflect the abnormal situation of the routing device.

[0093] The TLS handshake failure rate represents the proportion of the number of TLS handshake failures in the total number of TLS handshakes in a preset time period. When a man-in-the-middle attack occurs, the number of TLS handshake failures will significantly increase. In addition, when a certificate authentication problem occurs, the number of TLS handshake failures will also significantly increase, such as certificate expiration, domain name mismatch, and incomplete certificate chain. Therefore, the TLS handshake failure rate can also significantly reflect the abnormal situation of the routing device.

[0094] Therefore, based on the above four features, the target feature matrix in the embodiments of the present application can be obtained.

[0095] When the N pieces of real-time network traffic data shown in Table 1 are obtained, the maximum packet size in the preset time period, the average packet size in the preset time period, the number of short connections in the preset time period (judged according to a preset duration threshold, such as less than or equal to 2 seconds to be judged as a short connection), the total number of connections in the preset time period, the number of TLS handshake failures in the preset time period, the total number of TLS handshakes in the preset time period, the number of abnormal DNS queries in the preset time period (judged according to a preset query number threshold, such as greater than or equal to 75 times to be judged as an abnormal DNS query), and the total number of DNS queries in the preset time period can be determined.

[0096] For example, as shown in Table 1, the maximum packet size in the preset time period 8:00:00-8:00:50 is 1500, and the number of TLS handshake failures is 2.

[0097] In an optional implementation, when the above parameters are obtained, the burst traffic index can be calculated according to the maximum packet size and the average packet size. Specifically, the burst traffic index can be calculated by the following expression:

[0098]

[0099] wherein Max(Packet size) represents the maximum packet size;

[0100] Average(Packet size) represents the average packet size.

[0101] For example, as shown in Table 1, in the time period 8:00:00-8:00:50, the maximum packet size is 1500, and the average packet size is Average=(1500+300+1200+600+100+800) / 6=900.

[0102] Then, the final In the embodiments of the present application, the BI can reflect the fluctuation degree of data traffic, and the smaller the value is, the more stable the data traffic is.

[0103] In an optional embodiment, the proportion of short connections is calculated according to the number of short connections and the total number of connections. Specifically, the proportion of short connections can be calculated by the following expression:

[0104]

[0105] wherein, Number of Short-Lived Connections represents the number of short connections;

[0106] Total Connections represents the total number of connections.

[0107] For example, as shown in Table 1, in the time period of 8:00:00-8:00:50, the connection durations are 2 seconds, 0.8 seconds, 1.5 seconds, 3 seconds, 4 seconds, and 2.5 seconds, respectively, and the total number of connections is 6. If the preset duration threshold is less than or equal to 2 seconds, then the short connection durations are 2 seconds, 0.8 seconds, and 1.5 seconds, i.e., there are 3 short connections. Therefore, the proportion of short connections can be calculated as The higher the value of SCR is, the higher the possibility of scanning attack and other behaviors is.

[0108] In an optional embodiment, the TLS handshake failure rate can also be calculated according to the number of failed TLS handshakes and the total number of TLS handshakes. Specifically, the TLS handshake failure rate can be calculated by the following expression:

[0109]

[0110] wherein, Failed TLS Handshakes represents the number of failed TLS handshakes;

[0111] Total TLS Connections represents the total number of TLS handshakes.

[0112] For example, as shown in Table 1, in the time period of 8:00:00-8:00:50, there are 6 handshake verifications, which are success, failure, success, success, failure, and success, respectively. Therefore, it can be known that the total number of TLS handshakes is 6, and the number of failed TLS handshakes is 2. Thus, the TLS handshake failure rate can be calculated as The higher the value of THFR is, the higher the possibility of man-in-the-middle attack and other situations is.

[0113] In an alternative embodiment, the DNS query abnormality rate can also be calculated according to the number of abnormal DNS queries and the total number of DNS queries. Specifically, the DNS query abnormality rate can be calculated by the following expression:

[0114]

[0115] For example, as shown in Table 1, the number of DNS queries in the time period of 8:00:00-8:00:50 is 50, 60, 55, 75, 65, and 45, respectively. If the preset query number threshold is greater than or equal to 75, there is an abnormal DNS query, and the total number of DNS queries is 6. Then, the DNS query abnormality rate can be calculated as The higher the value of DQAR, the higher the possibility of malicious domain name query.

[0116] Further, a feature matrix can be formed according to the above four features. Referring to Table 2, an example of a feature matrix provided by an embodiment of the present application is shown.

[0117] For example, the feature matrix of the time periods of 8:00:00-8:00:59, 8:01:00-8:01:59, and 8:02:00-8:02:59 can be calculated according to the above method.

[0118] Table 2

[0119] Time period BI SCR DQAR THFR 8:00:00-8:00:59 1.67 0.5 0.17 0.33 8:01:00-8:01:59 1.58 0.33 0.33 0.33 8:02:00-8:02:59 1.68 0.33 0.17 0.17

[0120] Further, in order to eliminate the influence of different kinds of data dimensions and improve the detection accuracy of the model, the above four features need to be normalized. For example, the following normalization formula can be used to normalize each feature:

[0121]

[0122] where X represents the feature value corresponding to the feature to be normalized;

[0123] The minimum value represents the minimum feature value corresponding to the feature in each time period;

[0124] The maximum value represents the maximum feature value corresponding to the feature in each time period.

[0125] For example, if the BI in the time period of 8:00:00-8:00:59 is normalized, X = 1.67, the minimum value corresponding to the time period of 8:01:00-8:01:59 is 1.58, and the maximum value corresponding to the time period of 8:02:00-8:02:59 is 1.68. Then, according to the above normalization formula, we can get:

[0126] After the normalization of each feature in the above manner, the target feature matrix can be obtained. Referring to Table 3, a target feature matrix provided in an embodiment of the present application is shown.

[0127] Table 3

[0128] Time period BI SCR DQAR THFR 8:00:00-8:00:59 0.9 1 0 1 8:01:00-8:01:59 0 0 1 1 8:02:00-8:02:59 1 0 0 0

[0129] S2: Calculate a dynamic adjustment parameter based on the target feature matrix, and adjust the initial threat detection model according to the dynamic adjustment parameter to obtain a target threat detection model.

[0130] In the embodiment of the present application, the SVDD model can be used for threat detection. The SVDD model includes an input layer, the number of neurons of the input layer corresponding to the dimension of the input feature. In the embodiment of the present application, four features, BI, SCR, DQAR and THFR, are included. Therefore, the number of neurons in the input layer can be set to 4, and if other features are added later, the number of neurons can be further increased. Each neuron corresponds to receive a normalized feature value. The SVDD model also includes a hidden layer. In order to effectively capture the non-linear relationship and complex pattern between features, a structure of two hidden layers is set in the embodiment of the present application. The first hidden layer includes at least 16 neurons. As the dimension of the feature transmitted by the input layer increases, the number of neurons in the first hidden layer can be increased accordingly, and the ReLU activation function is used in the first hidden layer, which can effectively introduce non-linear relationship and alleviate the problem of gradient disappearance. In the second hidden layer, at least 8 neurons are included. Similarly, as the dimension of the feature transmitted by the input layer increases, the number of neurons in the second hidden layer can be increased accordingly, and the ReLU activation function is used. The second hidden layer further refines and compresses the information transmitted from the first hidden layer. The output layer can be set to 3 neurons in the embodiment of the present application. The output of the output layer is the coordinate of the data point in the latent space. The hypersphere center is initialized before the training starts, and the mean of the mapping points in the latent space is calculated by one forward propagation of all training data, and the mean is fixed as the center C of the hypersphere.

[0131] When training the SVDD model, the purpose can be to minimize the objective function. In the embodiment of the present application, the objective function is as follows:

[0132]

[0133] wherein n represents the number of training samples;

[0134] x represents a samplei a point in the latent space mapped by a network with weights W;

[0135] C is a fixed hypersphere center;

[0136] denotes the squared Euclidean distance from the sample mapping point to the hypersphere center C;

[0137] ‖W‖ 2 denotes the L2 norm of the neural network weights;

[0138] denotes a dynamic adjustment parameter, used to control the balance between the regularization strength (to prevent overfitting) and the fitting target (to minimize the hypersphere), and can control the complexity of the model.

[0139] In training the model, an Adam optimizer can be used to minimize the above objective function until the objective function is minimized, obtaining an initial threat detection model.

[0140] In the embodiments of the present application, in order to more accurately implement threat detection for routing devices, it is also necessary to dynamically adjust the dynamic adjustment parameter λ of the initial threat detection model according to the target feature matrix, so that the model can better adapt to the changes in the traffic characteristics of the routing device, thereby improving the accuracy and adaptability of the model for threat detection.

[0141] In an optional implementation, first, a first dynamic adjustment parameter, a second dynamic adjustment parameter, a third dynamic adjustment parameter, a target feature matrix, and a weight parameter set corresponding to the target feature matrix are obtained.

[0142] In the embodiments of the present application, the first dynamic adjustment parameter can be the dynamic adjustment parameter currently used by the initial threat detection model, such as being set to 1e-5. The second dynamic adjustment parameter can be an upper limit value of the dynamic adjustment parameter. The third dynamic adjustment parameter can be a lower limit value of the dynamic adjustment parameter. By setting the upper limit value and the lower limit value corresponding to the dynamic adjustment parameter, the dynamic adjustment parameter can be kept within a reasonable range, avoiding over-regularization or overfitting of the model.

[0143] And the weight parameter set sets a corresponding weight for each feature, which can be set according to the actual application scenario, for example, BI can be more easily predicted to attack, so the weight corresponding to BI is set higher. For example, the weight corresponding to BI is set to 0.4, the weight corresponding to SCR is set to 0.2, the weight corresponding to DQAR is set to 0.2, and the weight corresponding to THFR is set to 0.2.

[0144] In an embodiment, the dynamic adjustment parameter can be calculated by the following expression: λ = min(max(λ0*(1+α1*BI+α2*SCR+α3*DQAR+α4*THFR), λ min ), λ max )

[0145] wherein λ0represents a first dynamic adjustment parameter;

[0146] λ max represents a second dynamic adjustment parameter;

[0147] λ min represents a third dynamic adjustment parameter;

[0148] α1represents a weight corresponding to BI;

[0149] α2represents a weight corresponding to SCR;

[0150] α3represents a weight corresponding to DQAR;

[0151] α4represents a weight corresponding to THAR.

[0152] In the embodiments of the present application, the dynamic adjustment strategy is used to adjust the dynamic adjustment parameter of the model according to the traffic characteristics of the routing device, so as to better control the balance between the regularization strength (to prevent overfitting) and the fitting target (to minimize the hypersphere), and to control the complexity of the model. The initial threat detection model is adjusted according to the dynamic adjustment parameter, so as to obtain a target threat detection model for actual detection.

[0153] S3: using the target threat detection model to detect whether N pieces of real-time network traffic data are abnormal.

[0154] In the embodiments of the present application, after obtaining the target threat detection model, the target feature matrix corresponding to the N pieces of real-time network traffic data is input into the target threat detection model, so as to obtain the detection result of the output of the target threat detection model. The detection result can represent that the N pieces of real-time network traffic data are abnormal or are not abnormal.

[0155] In the embodiments of the present application, based on the traffic characteristics of the routing device, the SVDD model is used to detect the threat of the routing device. Since the four types of unique features are used, the abnormal data can be mapped outside the hypersphere, so as to improve the accuracy of the threat detection of the routing device.

[0156] Further, based on the same technical concept, the embodiments of the present application provide a router threat detection device for implementing the above method flow of the embodiments of the present application. Referring to Figure 3As shown, the device comprises a calculation module 301, an adjustment module 302, and a detection module 303, wherein,

[0157] The calculation module 301 is configured to calculate a target feature matrix based on the N pieces of real-time network traffic data; wherein the target feature matrix at least comprises a burst traffic intensity index representing the fluctuation degree of the traffic data of the routing device within a preset time period, a short connection proportion representing the proportion of the number of short connections in the total number of connections, a DNS query anomaly rate representing the proportion of the number of abnormal DNS queries in the total number of DNS queries, and a TLS handshake failure rate representing the proportion of the number of TLS handshake failures in the total number of TLS handshakes.

[0158] The adjustment module 302 is configured to calculate a dynamic adjustment parameter based on the target feature matrix, and adjust the parameters of an initial threat detection model according to the dynamic adjustment parameter to obtain a target threat detection model; wherein the dynamic adjustment parameter is used to limit the regularization degree and complexity of the target threat detection model.

[0159] The detection module 303 detects whether the N pieces of real-time network traffic data are abnormal by using the target threat detection model.

[0160] In an optional implementation, when the target feature matrix is calculated based on the N pieces of real-time network traffic data, the calculation module 301 is specifically configured to:

[0161] Obtain the maximum packet size, the average packet size, the number of short connections, the total number of connections, the number of TLS handshake failures, the total number of TLS handshakes, the number of abnormal DNS queries, and the total number of DNS queries corresponding to the N pieces of real-time network traffic data;

[0162] Calculate the burst traffic intensity index according to the maximum packet size and the average packet size;

[0163] Calculate the short connection proportion according to the number of short connections and the total number of connections;

[0164] Calculate the TLS handshake failure rate according to the number of TLS handshake failures and the total number of TLS handshakes;

[0165] Calculate the DNS query anomaly rate according to the number of abnormal DNS queries and the total number of DNS queries;

[0166] Obtain the target feature matrix based on the burst traffic intensity index, the short connection proportion, the TLS handshake failure rate, and the DNS query anomaly rate.

[0167] In an optional implementation, when the target threat detection model is obtained by calculating a dynamic adjustment parameter based on the target feature matrix and adjusting the parameters of an initial threat detection model according to the dynamic adjustment parameter, the adjustment module 302 is specifically configured to:

[0168] obtain a first dynamic adjustment parameter, a second dynamic adjustment parameter, a third dynamic adjustment parameter, a target feature matrix, and a weight parameter set corresponding to the target feature matrix; the first dynamic adjustment parameter is a dynamic adjustment parameter currently used by the initial threat detection model, the second dynamic adjustment parameter is used to indicate an upper limit value of the dynamic adjustment parameter, the third dynamic adjustment parameter is used to indicate a lower limit value of the dynamic adjustment parameter, and each weight parameter in the weight parameter set corresponds to a target feature in the target feature matrix;

[0169] According to the first dynamic adjustment parameter, the second dynamic adjustment parameter, the third dynamic adjustment parameter, the target feature matrix, and the weight parameter set corresponding to the target feature matrix, a dynamic adjustment parameter is calculated.

[0170] According to the dynamic adjustment parameter, the initial threat detection model is adjusted to obtain a target threat detection model.

[0171] In an optional implementation, when the target threat detection model is used to detect whether N pieces of real-time network traffic data are abnormal, the detection module 303 is specifically configured to:

[0172] input the target feature matrix into the target threat detection model;

[0173] determine whether the N pieces of real-time network traffic data are abnormal according to a detection result output by the target threat detection model.

[0174] Based on the same technical concept, the embodiments of the present application also provide an electronic device, which can implement the router threat detection method process provided by the above-mentioned embodiments of the present application. In an embodiment, the electronic device can be a server, a terminal device or other electronic device. Referring to Figure 4 As shown in the figure, the electronic device can include:

[0175] at least one processor 401 and a memory 402 connected with the at least one processor 401, and the specific connection medium between the processor 401 and the memory 402 is not limited in the embodiments of the present application, Figure 4 for example, the connection between the processor 401 and the memory 402 through the bus 400. The bus 400 is represented by a thick line in Figure 4 the figure, and the connection mode between other components is only schematically illustrated and is not limited. The bus 400 can be divided into an address bus, a data bus, a control bus, etc., for convenience, Figure 4 in the figure, only one thick line is used to represent, but it does not mean that there is only one bus or only one type of bus. Alternatively, the processor 401 can also be called a controller, and the name is not limited.

[0176] In the embodiments of the present application, the memory 402 stores instructions executable by the at least one processor 401, and the at least one processor 401 can execute the foregoing method of detecting threats of a router by executing the instructions stored in the memory 402. The processor 401 can implement Figure 3 the functions of various modules of the apparatus shown.

[0177] The processor 401 is the control center of the apparatus, and can connect all parts of the control device through various interfaces and lines, and monitor the whole apparatus by running or executing the instructions stored in the memory 402 and calling the data stored in the memory 402, so as to process data and implement various functions of the apparatus.

[0178] In a possible design, the processor 401 can include one or more processing units, and the processor 401 can integrate an application processor and a modem processor, where the application processor mainly processes an operating system, a user interface, and an application program, and the modem processor mainly processes wireless communication. It can be understood that the foregoing modem processor can also not be integrated into the processor 401. In some embodiments, the processor 401 and the memory 402 can be implemented on the same chip, and in some embodiments, they can also be implemented on separate chips respectively.

[0179] The processor 401 can be a general-purpose processor, for example, a CPU, a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, and can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method of detecting threats of a router disclosed in the embodiments of the present application can be directly embodied as execution completed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0180] The memory 402, as a non-volatile computer readable storage medium, can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 402 can include at least one type of storage medium, for example, can include flash memory, hard disk, multimedia card, card type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. The memory 402 is any other medium capable of carrying or storing desired program code in the form of instructions or data structures and capable of being accessed by a computer, but is not limited to this. The memory 402 in the embodiments of the present application can also be a circuit or any other device capable of realizing a storage function, used to store program instructions and / or data.

[0181] By designing and programming the processor 401, the code corresponding to the router threat detection method introduced in the foregoing embodiments can be fixed into the chip, so that the chip can execute the steps of the router threat detection method of the embodiments shown in the running time. Figure 2 How to design and program the processor 401 is a technology known to those skilled in the art, which will not be described here.

[0182] Based on the same inventive concept, the embodiments of the present application also provide a storage medium storing computer instructions, when the computer instructions run on a computer, the computer instructions make the computer execute the router threat detection method discussed above.

[0183] In some possible implementations, the present application also provides various aspects of a router threat detection method, which can also be implemented in the form of a program product, including program code, when the program product runs on a device, the program code is used to make the control device execute the steps of the router threat detection method according to various exemplary embodiments of the present application described above in the specification.

[0184] It should be noted that, although several units or sub-units of the apparatus are mentioned in the above detailed description, such division is merely exemplary and not mandatory. Indeed, according to an embodiment of the application, the features and functionalities of two or more units described above can be embodied in one unit. Conversely, the features and functionalities of one unit described above can be further divided into units embodied by several units.

[0185] Moreover, although the operations of the method(s) herein can be described in a particular, sequential order, this order is not meant to be a limitation and is not intended to imply that

[0186] Those of skill in the art would understand that embodiments of the present application can be provided as a method, a system, or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, and the like) embodying computer readable program code.

[0187] The present application is described in reference to the flowchart illustrations and / or block diagrams of the methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing system or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 The means for carrying out the functions specified in the flowchart illustrations and / or block diagrams can be embodied in one or more of the following: Figure 1 The means for carrying out the functions specified in the flowchart illustrations and / or block diagrams can be embodied in one or more of the following:

[0188] The program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, C++, or the like, and conventional procedural programming languages, such as the "C" programming language, or the like. The program code can execute entirely on the user's computing device, partly on the user's device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote computing device or server.

[0189] These computer program instructions can also be loaded into a computer or other programmable data processing devices, so that a series of operational steps are performed on the computer or other programmable data processing devices to generate computer-implemented processes, thus the instructions executed on the computer or other programmable data processing devices provide processes for implementing the functions specified in the flowchart Figure 1 flowchart or multiple flows and / or blocks Figure 1 flowchart or multiple flows and / or blocks

[0190] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.

Claims

1. A router threat detection method, characterized in that: The method comprises: Calculate a target feature matrix based on N pieces of real-time network traffic data; wherein the target feature matrix includes at least: a burst traffic intensity index, which represents the degree of fluctuation of traffic data of the routing device within a preset time period; a short connection ratio, which represents the proportion of short connections in the total number of connections; a DNS query anomaly rate, which represents the proportion of abnormal DNS queries in the total number of DNS queries; and a TLS handshake failure rate, which represents the proportion of TLS handshake failures in the total number of TLS handshakes; Calculating dynamic adjustment parameters based on the target feature matrix, and adjusting parameters of the initial threat detection model according to the dynamic adjustment parameters to obtain a target threat detection model; wherein the dynamic adjustment parameters are used to limit the regularization degree and complexity of the target threat detection model; The target threat detection model is used to detect whether the N pieces of real-time network traffic data are abnormal.

2. The method according to claim 1, wherein The target feature matrix is ​​calculated based on N pieces of real-time network traffic data, including: Get the maximum packet size, average packet size, number of short connections, total number of connections, number of TLS handshake failures, total number of TLS handshakes, number of abnormal DNS queries, and total number of DNS queries corresponding to N real-time network traffic data; Calculating the burst traffic intensity index according to the maximum data packet size and the average data packet size; Calculate the short connection ratio based on the number of short connections and the total number of connections; Calculate the TLS handshake failure rate based on the number of TLS handshake failures and the total number of TLS handshakes; Calculate the DNS query abnormality rate based on the number of abnormal DNS queries and the total number of DNS queries; The target feature matrix is ​​obtained based on the burst traffic intensity index, the short connection ratio, the TLS handshake failure rate, and the DNS query anomaly rate.

3. The method according to claim 1, wherein The step of calculating the dynamic adjustment parameters based on the target feature matrix and adjusting the parameters of the initial threat detection model according to the dynamic adjustment parameters to obtain the target threat detection model includes: Obtaining a first dynamic adjustment parameter, a second dynamic adjustment parameter, a third dynamic adjustment parameter, the target feature matrix, and a weight parameter set corresponding to the target feature matrix; wherein the first dynamic adjustment parameter is a dynamic adjustment parameter currently used by the initial threat detection model, the second dynamic adjustment parameter is used to indicate an upper limit value of the dynamic adjustment parameter, the third dynamic adjustment parameter is used to indicate a lower limit value of the dynamic adjustment parameter, and each weight parameter in the weight parameter set corresponds to a target feature in the target feature matrix; Calculating the dynamic adjustment parameter according to the first dynamic adjustment parameter, the second dynamic adjustment parameter, the third dynamic adjustment parameter, the target feature matrix, and a set of weight parameters corresponding to the target feature matrix; The initial threat detection model is parameter-adjusted according to the dynamic adjustment parameters to obtain the target threat detection model.

4. The method according to claim 1, wherein The detecting whether the N pieces of real-time network traffic data are abnormal using the target threat detection model includes: Inputting the target feature matrix into the target threat detection model; Determine whether the N pieces of real-time network traffic data are abnormal based on the detection results output by the target threat detection model.

5. A router threat detection device, characterized in that: The device comprises: A calculation module is configured to calculate a target feature matrix based on N pieces of real-time network traffic data; wherein the target feature matrix includes at least: a burst traffic intensity index, which represents the degree of fluctuation of traffic data of a routing device within a preset time period; a short connection ratio, which represents the proportion of short connections in the total number of connections; a DNS query anomaly rate, which represents the proportion of abnormal DNS queries in the total number of DNS queries; and a TLS handshake failure rate, which represents the proportion of TLS handshake failures in the total number of TLF handshakes. an adjustment module, configured to calculate dynamic adjustment parameters based on the target feature matrix, and adjust parameters of the initial threat detection model according to the dynamic adjustment parameters to obtain a target threat detection model; wherein the dynamic adjustment parameters are used to limit the complexity of the target threat detection model; The detection module uses the target threat detection model to detect whether there are any anomalies in the N real-time network traffic data.

6. The device according to claim 5, characterized in that When calculating the target feature matrix based on N pieces of real-time network traffic data, the calculation module is specifically used to: Get the maximum packet size, average packet size, number of short connections, total number of connections, number of TLS handshake failures, total number of TLS handshakes, number of abnormal DNS queries, and total number of DNS queries corresponding to N real-time network traffic data; Calculating the burst traffic intensity index according to the maximum data packet size and the average data packet size; Calculate the short connection ratio based on the number of short connections and the total number of connections; Calculate the TLS handshake failure rate based on the number of TLS handshake failures and the total number of TLS handshakes; Calculate the DNS query abnormality rate based on the number of abnormal DNS queries and the total number of DNS queries; The target feature matrix is ​​obtained based on the burst traffic intensity index, the short connection ratio, the TLS handshake failure rate, and the DNS query anomaly rate.

7. The device according to claim 5, characterized in that When the dynamic adjustment parameters are calculated based on the target feature matrix, and the parameters of the initial threat detection model are adjusted according to the dynamic adjustment parameters to obtain the target threat detection model, the adjustment module is specifically configured to: Obtaining a first dynamic adjustment parameter, a second dynamic adjustment parameter, a third dynamic adjustment parameter, the target feature matrix, and a weight parameter set corresponding to the target feature matrix; wherein the first dynamic adjustment parameter is a dynamic adjustment parameter currently used by the initial threat detection model, the second dynamic adjustment parameter is used to indicate an upper limit value of the dynamic adjustment parameter, the third dynamic adjustment parameter is used to indicate a lower limit value of the dynamic adjustment parameter, and each weight parameter in the weight parameter set corresponds to a target feature in the target feature matrix; Calculating the dynamic adjustment parameter according to the first dynamic adjustment parameter, the second dynamic adjustment parameter, the third dynamic adjustment parameter, the target feature matrix, and a set of weight parameters corresponding to the target feature matrix; The initial threat detection model is parameter-adjusted according to the dynamic adjustment parameters to obtain the target threat detection model.

8. The device according to claim 5, wherein When the target threat detection model is used to detect whether the N pieces of real-time network traffic data are abnormal, the detection module is specifically configured to: Inputting the target feature matrix into the target threat detection model; Determine whether the N pieces of real-time network traffic data are abnormal based on the detection results output by the target threat detection model.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 4 is implemented.

10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the method according to any one of claims 1 to 4 is implemented.