Network anomaly perception early warning method and system
By dynamically adjusting the sampling frequency and multiple constraints, the network anomaly perception and early warning method solves the problem that existing technologies cannot fully capture multi-dimensional feature correlations and complex anomaly identification, achieving accurate identification and timely protection of network anomalies, and improving the effectiveness and continuity of network security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- JINAN GUANGPENG SIZHAN TECH CO LTD
- Filing Date
- 2026-04-10
- Publication Date
- 2026-05-29
AI Technical Summary
Existing technologies are unable to fully reflect the temporal correlation patterns of network interactions, data structure matching relationships, and consistency of user operations, and cannot accurately identify complex anomaly patterns. Furthermore, binary anomaly results cannot be transformed into targeted protective measures, thus limiting the timeliness and effectiveness of network security protection.
By collecting process parameter configuration datasets from the data transmission link in real time, dynamically adjusting the sampling frequency, and performing group analysis based on multiple constraints and anomaly correlation scores, a task feature identifier-anomaly data mapping table is generated. Combined with the degree of anomaly correlation, a graded response strategy is implemented to achieve accurate capture and targeted protection of multi-dimensional feature correlations.
It enables accurate identification and timely protection against network anomalies, avoids data bias and misjudgment, improves the effectiveness and continuity of network security protection, and provides clear logical clues for anomaly analysis and protective measures.
Smart Images

Figure CN122120009A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a method and system for network anomaly detection and early warning. Background Technology
[0002] With the digital transformation of enterprises, the protection requirements for the security of daily production, business, and network systems have become particularly important, among which network anomaly detection is a crucial part of security maintenance. Traditional network anomaly detection methods typically extract single-dimensional features from network interaction data, such as time intervals or field matching, and call traditional models such as rule engines or support vector machines to determine anomalies, outputting only a binary result of abnormal or normal, and the detection results are mostly used for log recording or manual alerts. However, existing technologies cannot comprehensively reflect the temporal correlation patterns of network interactions, data structure matching relationships, and consistency of user operations, and cannot capture the implicit correlations between different dimensional features, leading to inaccurate identification of complex anomaly patterns. At the same time, binary anomaly results cannot clearly define the specific manifestation of the anomaly, making it difficult to directly translate into targeted protective measures, thus limiting the timeliness and effectiveness of network security protection. Therefore, how to more accurately identify network anomaly behavior and promote the transformation of detection results into protective actions has become a current research hotspot in the field of network security. Summary of the Invention
[0003] In view of this, the purpose of the present invention is to provide a network anomaly detection and early warning method and system to solve the technical problems mentioned in the prior art.
[0004] The network anomaly detection and early warning method includes the following steps:
[0005] Within a preset data detection time sequence, the process parameter configuration dataset of the data transmission link is collected in real time and normalized to construct several parameter sequences. The initial sampling frequency of each sub-parameter in the process parameter configuration dataset is set based on task priority, and the initial sampling frequency of each sub-parameter is dynamically adjusted according to an anomaly pre-triggering mechanism. The anomaly pre-triggering mechanism is set as follows: when the current data change rate of any sub-parameter in the process parameter configuration dataset approaches or exceeds the anomaly pre-triggering threshold, the current sampling frequency of the sub-parameter is increased to several times the previous sampling frequency; when the current data change rate of any sub-parameter does not exceed the anomaly pre-triggering threshold, the current sampling frequency of the sub-parameter is restored to the initial sampling frequency.
[0006] Several parameter sequences are divided into several candidate groups based on a first and a second preset constraint. The first constraint is to set the number of candidate groups corresponding to several task feature identifiers in the process parameter configuration dataset. The second constraint is to retrieve abnormal values from the parameter sequences based on the task execution deviation set by the parameter anomaly detection range, and divide the abnormal values into the corresponding candidate groups according to the parameter sequences whose task data streams corresponding to the task feature identifiers have a similarity greater than the preset feature vectors, generating several task feature identifier-abnormal data mapping tables.
[0007] Based on each candidate group, the degree of abnormal correlation of parameter sequences within the group is analyzed, the abnormal correlation score of each candidate group is calculated, and the candidate groups are divided into a first-level response pool and a second-level response pool based on the abnormal correlation score.
[0008] For candidate groups in the primary response pool, if the detection resources for each candidate group in the secondary response pool are determined, the remaining detection resources are selected to trigger the perception evaluation task based on the anomaly association score.
[0009] For candidate groups in the secondary response pool, execute the abnormal response strategy.
[0010] Optionally, the sub-parameters of the process parameter configuration dataset include at least one of network parameters, target parameters, and process parameters;
[0011] The target parameters are configured with multiple continuous task data streams within a preset data detection time sequence according to the process execution flow, and the multiple continuous task data streams are sequentially sent to the execution unit according to the data transmission link configured by the network parameters to output the corresponding process parameters.
[0012] Optionally, the task priorities of the process parameter configuration dataset are set in descending order as follows: core parameters, auxiliary parameters, and redundant parameters;
[0013] The core parameters include at least the data stream transmission rate and task delay response command of the process parameters, as well as the bandwidth utilization rate in the network parameters;
[0014] The auxiliary parameters include at least the task feature identifier of the target parameter and the node load data of the network parameter;
[0015] The redundant parameters include at least the historical transmission record backup data of the process parameters.
[0016] Optionally, the method for calculating the abnormal correlation score specifically includes:
[0017] The absolute value of the difference between the completion matching degree of all task data streams of the target parameters and process parameters in the same candidate group at any detection node in the current data detection time sequence and the preset standard completion rate is obtained to obtain the process execution deviation sequence. The process execution deviation sequence is used as the key indicator of the abnormal correlation score.
[0018] Optionally, the anomaly correlation score is at least one of the mean and variance of the absolute values of the differences corresponding to any one or more task data streams in the process execution deviation sequence under multiple consecutive detection nodes.
[0019] Optionally, the method for dividing candidate groups into a primary response pool and a secondary response pool based on anomaly correlation scores specifically includes:
[0020] According to the grouping rules set by the scoring criteria of the abnormal correlation score, the candidate groups are divided into a first-level response pool and a second-level response pool; the grouping rules are as follows: the candidate groups whose abnormal correlation scores are within the preset monitoring threshold range and / or the candidate groups whose completion matching degree dispersion of all task data streams in the abnormal correlation scores is within the preset range are divided into the first-level response pool, and the remaining candidate groups are divided into the second-level response pool.
[0021] Optionally, the evaluation strategy for the perception evaluation task specifically includes:
[0022] Obtain the task execution deviation between the target parameter and the process parameter in any candidate group. The task execution deviation is the absolute value of the difference between the completion matching degree of the same task data stream of the target parameter and the process parameter and the preset standard completion rate. When the task execution deviation exceeds the parameter anomaly detection range of the corresponding detection node in the current data detection time sequence, calculate the data operation deviation values of each data in the current data transmission link based on the real-time data of the network parameters, and generate a network anomaly analysis report.
[0023] The data for the current data transmission link includes at least bandwidth utilization and node load data.
[0024] Optionally, the method for implementing the exception response strategy specifically includes:
[0025] Based on the data transmission stability of the task data stream corresponding to each task feature identifier in the anomaly correlation score, any mode of the collaborative early warning instruction is dynamically executed, triggering the early warning module to issue an early warning message or push the early warning message to the user terminal. The collaborative early warning instruction includes:
[0026] Low-level early warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by less than 5%, and the degree of dispersion of the completion matching degree of all task data streams in the abnormal correlation score tends to be concentrated, then a first-level early warning instruction is generated to control the data transmission link to retrieve the historical transmission record backup data of the process parameters under the corresponding detection node and send it to the execution unit to update the source data in real time.
[0027] Intermediate warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range of 5%-10%, and / or the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to diverge, then a secondary warning instruction is generated to control the data transmission link to send a task delay response instruction to the execution unit.
[0028] Advanced warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by 10%, and the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to be concentrated, then a level 3 warning command is generated to control the data transmission link to be shut down.
[0029] A network anomaly detection and early warning system, applied in the above-described method, the system comprising:
[0030] The parameter acquisition module, whose data acquisition port is connected to a designated port of the network transmission device, is used to acquire the process parameter configuration dataset of the data transmission link in real time within a preset data detection time sequence, and normalize it into several parameter sequences. The process parameter configuration dataset sets the initial sampling frequency of each sub-parameter based on task priority, and the initial sampling frequency of each sub-parameter is dynamically adjusted according to an anomaly pre-triggering mechanism. The anomaly pre-triggering mechanism is set as follows: when the current data change rate of any sub-parameter in the process parameter configuration dataset approaches or exceeds the anomaly pre-triggering threshold, the current sampling frequency of that sub-parameter is increased to several times the previous sampling frequency; when the current data change rate of any sub-parameter does not exceed the anomaly pre-triggering threshold, the current sampling frequency of that sub-parameter is restored to the initial sampling frequency.
[0031] An anomaly scheduling module is used to divide a number of parameter sequences into several candidate groups based on a first constraint and a second constraint. The first constraint is to set a number of candidate groups that correspond one-to-one with several task feature identifiers in the process parameter configuration dataset. The second constraint is to retrieve abnormal values from the parameter sequences based on the task execution deviation set by the parameter anomaly detection range, and divide the abnormal values into the corresponding candidate groups according to the parameter sequences whose task data streams corresponding to the task feature identifiers have a similarity greater than a preset feature vector, generating several task feature identifier-abnormal data mapping tables.
[0032] The anomaly analysis module analyzes the degree of abnormal correlation of parameter sequences within each candidate group, calculates the anomaly correlation score of each candidate group, and divides the candidate groups into a primary response pool and a secondary response pool based on the anomaly correlation score.
[0033] The anomaly response module, for candidate groups in the primary response pool, if the detection resources for each candidate group in the secondary response pool are determined, combines the anomaly association score to select the remaining detection resources to trigger the perception evaluation task; for candidate groups in the secondary response pool, it executes the anomaly response strategy.
[0034] Optionally, the sub-parameters of the process parameter configuration dataset in the parameter acquisition module include network parameters, target parameters, and process parameters; the target parameters are configured with multiple continuous task data streams within a preset data detection sequence according to the process execution flow, and the multiple continuous task data streams are sequentially sent to the execution unit according to the data transmission link configured by the network parameters to output the corresponding process parameters;
[0035] The anomaly analysis module is used to obtain the absolute value of the difference between the completion matching degree of all task data streams of target parameters and process parameters in the same candidate group at any detection node in the current data detection time sequence and the preset standard completion rate, to obtain the process execution deviation sequence, and use the process execution deviation sequence as the key indicator of the anomaly association score;
[0036] The anomaly correlation score is at least one of the mean and variance of the absolute values of the differences corresponding to any one or more task data streams in the process execution deviation sequence under multiple consecutive detection nodes; the mean is used to reflect whether the anomaly correlation score is within a preset monitoring threshold range; the variance is used to reflect whether the degree of dispersion of the completion matching of all task data streams in the anomaly correlation score is within a preset interval; at the same time, the candidate group is divided into a primary response pool and a secondary response pool according to the grouping rules set by the scoring criteria of the anomaly correlation score.
[0037] Specifically, when the anomaly response module selects remaining detection resources to trigger a perception evaluation task for a candidate group in the primary response pool, it obtains the task execution deviation between the target parameter and the process parameter in any candidate group. This task execution deviation is the absolute value of the difference between the completion matching degree of the same task data stream of the target parameter and the process parameter and the preset standard completion rate. When the task execution deviation exceeds the parameter anomaly detection range of the corresponding detection node within the current data detection time sequence, it calculates the data operation deviation values of each item in the current data transmission link based on real-time data of network parameters and generates a network anomaly analysis report. The data of the current data transmission link includes at least bandwidth utilization and node load data.
[0038] The anomaly response module executes anomaly response strategies for candidate groups in the secondary response pool. Based on the data transmission stability of the task data stream corresponding to each task feature identifier in the anomaly association score, it dynamically executes any mode of the collaborative early warning instruction and triggers the early warning module to issue an early warning message or push the early warning message to the user terminal. The collaborative early warning instruction includes:
[0039] Low-level early warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by less than 5%, and the degree of dispersion of the completion matching degree of all task data streams in the abnormal correlation score tends to be concentrated, then a first-level early warning instruction is generated to control the data transmission link to retrieve the historical transmission record backup data of the process parameters under the corresponding detection node and send it to the execution unit to update the source data in real time.
[0040] Intermediate warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range of 5%-10%, and / or the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to diverge, then a secondary warning instruction is generated to control the data transmission link to send a task delay response instruction to the execution unit.
[0041] Advanced warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by 10%, and the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to be concentrated, then a level 3 warning command is generated to control the data transmission link to be shut down.
[0042] The beneficial effects that this invention can produce include:
[0043] 1. The network anomaly perception and early warning method and system provided by this invention collects process parameter configuration datasets of data transmission links in real time within a preset detection sequence and normalizes them to construct a multi-dimensional parameter sequence. At the same time, it sets the initial sampling frequency of sub-parameters based on task priority and dynamically adjusts the initial sampling frequency through an anomaly pre-triggering mechanism: if the data change rate of any sub-parameter approaches or exceeds the threshold, the sampling frequency is increased; otherwise, the initial value is restored. This can accurately capture anomaly precursors, thereby breaking the limitations of traditional single-dimensional extraction, comprehensively collecting multiple parameters such as network, target, and process parameters, avoiding data bias, and providing solid data support for anomaly analysis and early warning.
[0044] 2. This invention groups parameter sequences using dual constraints, setting the number of candidate groups based on task feature identifiers and retrieving outlier values within the anomaly detection range. Then, a cosine similarity algorithm is used to partition the parameter sequences, generating a task feature identifier-anomaly data mapping table to achieve scientific grouping and association with anomaly data. This grouping method can uncover implicit correlations between parameter sequences, overcoming the shortcomings of traditional methods in capturing multi-dimensional feature associations and inaccurate identification of complex anomalies. It also provides a clear grouping foundation for anomaly association analysis, improving the targeting of anomaly identification, avoiding interference from irrelevant parameters, and increasing analysis efficiency. Furthermore, by refining the sub-parameter classification, clarifying the target parameter task data flow distribution logic and the inherent relationships between parameters, it further strengthens the ability to capture multi-dimensional feature associations, facilitating accurate location of network anomaly root causes, providing clear logical clues for anomaly attribution, and assisting in subsequent anomaly investigation and control.
[0045] 3. This invention uses the absolute value of the difference between the task matching degree of target parameters and process parameters at each detection node and the standard value as the core indicator. It quantifies the degree of anomaly through mean and variance, making the calculation more scientific and operable, and accurately capturing implicit correlations between parameters. Simultaneously, it combines anomaly correlation scores with the dispersion of matching degree to comprehensively stratify the data, avoiding subjectivity in hierarchical classification. This provides accurate data support for differentiated perception, assessment, and response strategies, prioritizing resource allocation to parameters with high anomaly levels. It implements a prevention-then-inquiry response strategy, replacing traditional binary anomaly judgment results and directly transforming them into targeted protective measures, ensuring the timeliness and effectiveness of network security protection and preventing the expansion of hidden dangers. This early warning method integrates multi-detection node data for comprehensive evaluation, avoiding misjudgments of instantaneous anomalies, ensuring network and process production continuity, and improving the reliability of anomaly identification. Therefore, it effectively solves the problems of traditional methods failing to capture multi-dimensional feature correlations and inaccurate identification of complex anomalies. Attached Figure Description
[0046] Figure 1 This is a flowchart of the network anomaly detection and early warning method of the present invention;
[0047] Figure 2 In this invention Figure 1 Flowchart of the steps for dividing the primary / secondary response pools. Detailed Implementation
[0048] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0049] Please see Figure 1As shown, the present invention provides a network anomaly detection and early warning method, comprising the following steps:
[0050] Within a preset data detection time sequence, process parameter configuration datasets from the data transmission link are collected in real time and normalized to construct several parameter sequences. The initial sampling frequency of each sub-parameter in this process parameter configuration dataset is set based on task priority, and the initial sampling frequency of each sub-parameter is dynamically adjusted according to an anomaly pre-triggering mechanism. The anomaly pre-triggering mechanism is set as follows: when the current data change rate of any sub-parameter in the process parameter configuration dataset approaches or exceeds the anomaly pre-triggering threshold, the current sampling frequency of that sub-parameter is increased to several times the previous sampling frequency; when the current data change rate of any sub-parameter does not exceed the anomaly pre-triggering threshold, the current sampling frequency of that sub-parameter is restored to the initial sampling frequency. This overcomes the limitations of traditional single-dimensional feature extraction, achieves comprehensive collection of multi-dimensional data, and avoids the one-sidedness of single-dimensional data. Furthermore, dynamic sampling can accurately capture early signs of parameter anomalies, improving the accuracy of anomaly detection and providing comprehensive and accurate data support for subsequent anomaly analysis and early warning. In addition, this anomaly pre-triggering mechanism calculates the data change rate of each sub-parameter in real time through a sliding window, and the size of the sliding window can be adjusted according to the time series length. It also dynamically corrects the anomaly pre-triggering threshold by combining historical fluctuation trends, such as by using an exponentially weighted moving average algorithm, further enhancing the ability to identify slowly changing anomalies. The correction value of the anomaly pre-triggering threshold is the sum of the current anomaly pre-triggering threshold multiplied by a weight coefficient and the historical anomaly pre-triggering threshold multiplied by (1-weight coefficient), where the weight coefficient is between 0.3 and 0.4. At the same time, the timestamp and triggering reason are recorded synchronously for all sampling frequency adjustment processes, forming a traceable parameter evolution log, which facilitates subsequent anomaly attribution analysis and system iterative optimization.
[0051] By using a first and a second pre-defined constraint, several parameter sequences are divided into several candidate groups. The first constraint is: based on several task feature identifiers in the configuration dataset of process parameters, such as process task ID, execution node ID, or process type extracted from the target parameters, a number of candidate groups are set to correspond one-to-one with each identifier. The second constraint is: based on the parameter anomaly detection range, such as the task execution deviation set by the normalized value, outliers are retrieved from the parameter sequences, and the outliers are divided into corresponding candidate groups according to the parameter sequences whose task data streams corresponding to the task feature identifiers have a similarity greater than a pre-defined feature vector. This generates several task feature identifier-outlier data mapping tables, where each parameter sequence is converted into a feature vector, such as a normalized value, and the cosine similarity algorithm is used to calculate the feature vector similarity of the task feature identifiers. Thus, by using dual constraints, multi-dimensional parameter sequences are grouped, task feature identifiers are associated with outliers, and the correlation between parameter sequences is explored. This achieves classification and aggregation of multi-dimensional parameter features, captures implicit correlations between different parameter sequences, and solves the shortcomings of traditional methods in capturing implicit correlations of multi-dimensional features and inaccurate identification of complex anomaly patterns. At the same time, it provides a clear grouping basis for subsequent anomaly correlation analysis and improves the targeting of anomaly identification.
[0052] Based on each candidate group, the degree of abnormal correlation of parameter sequences within the group is analyzed, and the abnormal correlation score of each candidate group is calculated. Based on the abnormal correlation score, the candidate groups are divided into a primary response pool and a secondary response pool. This approach quantifies the degree of abnormality by introducing anomaly correlation scores, replacing traditional binary anomaly results. Furthermore, the construction of tiered response pools enables differentiated handling of anomalies, providing a basis for subsequent targeted protection measures and improving the timeliness of protection. Specifically, for candidate groups in the primary response pool, if the detection resources for each candidate group in the secondary response pool are determined, the remaining detection resources, such as unused analysis computing power and data detection nodes, are selected to trigger a perception assessment task based on the abnormal correlation score. For candidate groups in the secondary response pool, anomaly response strategies are executed. Thus, through tiered responses, detection resources can be rationally allocated, avoiding waste, while simultaneously conducting in-depth investigations of potential anomalies. This overcomes the shortcomings of traditional methods that only record logs and alarms, failing to provide in-depth anomaly analysis, further improving the accuracy of anomaly identification, providing more detailed anomaly information for subsequent protection measures, and driving the transformation of detection results into protection operations. This achieves linkage between anomaly detection and protection operations, improving the effectiveness of network security protection and preventing the escalation of anomalies.
[0053] In the above, for parameter data of different dimensions and types, minimum-maximum normalization or Z-score standardization is used, and the normalized parameter sequences are classified and stored. Each parameter sequence corresponds to at least one sub-parameter. The sequence format of the sub-parameter consists of timestamp, normalized value, original value and sampling frequency.
[0054] Furthermore, the sub-parameters of the process parameter configuration dataset include at least one of network parameters, target parameters, and process parameters; the target parameters are configured with multiple continuous task data streams within a preset data detection time sequence according to the process execution flow, and the multiple continuous task data streams are sequentially sent to the execution unit according to the data transmission link configured by the network parameters to output the corresponding process parameters; by refining the specific implementation steps of multi-dimensional data, the inherent relationship between each sub-parameter can be reflected, thereby strengthening the correlation capture capability of multi-dimensional features and facilitating subsequent analysis of the root cause of network anomalies.
[0055] Furthermore, the task priorities of the process parameter configuration dataset are set in descending order as follows: core parameters, auxiliary parameters, and redundant parameters. Core parameters include at least the data stream transmission rate and task latency response instructions for process parameters, as well as the bandwidth utilization rate in network parameters. The initial sampling frequency for core parameters is 100-200ms / time. Auxiliary parameters include at least the task feature identifier of the target parameters and the node load data of network parameters. The initial sampling frequency for auxiliary parameters is 400-500ms / time. Redundant parameters include at least the historical transmission record backup data of process parameters. The initial sampling frequency for redundant parameters is 1-2s / time. Through differentiated management of each sub-parameter, the acquisition accuracy and detection resources of core parameters are prioritized, interference from irrelevant parameters is avoided, and the efficiency and accuracy of anomaly detection are improved. Simultaneously, redundant parameters provide historical reference data for anomaly tracing and the formulation of protective measures, solving the problems of unfocused and inefficient parameter acquisition in traditional methods, and enhancing the effective utilization of multi-dimensional features.
[0056] Furthermore, such as Figure 2 As shown, the calculation method for the anomaly correlation score specifically includes: obtaining the absolute value of the difference between the completion matching degree of all task data streams and the preset standard completion rate of the target parameter and process parameter in the same candidate group at any detection node within the current data detection time sequence, thus obtaining the process execution deviation sequence, which is used as the key indicator of the anomaly correlation score. Quantifying the key indicator makes the calculation of the anomaly correlation score more scientific and operable, facilitating the accurate capture of implicit correlations between parameters, such as the matching deviation between the target parameter and process parameter. This addresses the shortcomings of traditional methods in failing to capture implicit correlations of multi-dimensional features and inaccurate identification of complex anomaly patterns. It also provides a quantitative basis for anomaly classification and response strategies, avoiding subjectivity in anomaly degree judgment. Specifically, the anomaly correlation score is at least one of the mean and variance of the absolute values of the differences corresponding to any one or more task data streams in the process execution deviation sequence at multiple consecutive detection nodes. By integrating the collected data from multiple detection nodes for comprehensive evaluation, it is possible to avoid misjudgments caused by instantaneous network anomalies due to sudden events, ensuring the continuity of process production.
[0057] Furthermore, such as Figure 2 As shown, the method for dividing candidate groups into a primary response pool and a secondary response pool based on anomaly correlation scores specifically includes: dividing candidate groups into a primary response pool and a secondary response pool according to the grouping rules set by the anomaly correlation score scoring criteria; the grouping rules are: candidate groups whose anomaly correlation scores are within a preset monitoring threshold range and / or candidate groups whose completion matching degree dispersion of all task data streams in the anomaly correlation scores is within a preset interval are divided into the primary response pool, and the remaining candidate groups are divided into the secondary response pool. By clarifying the specific rules for anomaly classification and combining the numerical value and dispersion of the anomaly correlation scores for comprehensive evaluation and stratification, the subjectivity of classification is avoided, thereby providing accurate data support for subsequent differentiated perception assessment and response strategies. This allows for the priority allocation of detection resources to network parameters with high anomaly levels, and then the analysis of the causes of anomalies for network parameters with low anomaly levels based on the remaining detection resources, facilitating the accurate identification of fault points and realizing a prevention-then-inquiry protection strategy to prevent the continuous expansion of security risks.
[0058] Furthermore, the evaluation strategy for the perception and assessment task specifically includes: obtaining the task execution deviation between the target parameter and the process parameter in any candidate group. This task execution deviation is the absolute value of the difference between the completion matching degree of the same task data stream of the target parameter and the process parameter and the preset standard completion rate; when the task execution deviation exceeds the parameter anomaly detection range of the corresponding detection node within the current data detection time sequence, calculating the data operation deviation values of each item in the current data transmission link based on real-time data of network parameters, and generating a network anomaly analysis report; the data of the current data transmission link includes at least bandwidth utilization and node load data. Thus, by clarifying the specific manifestations of anomalies, such as the task execution deviation of process-issued instructions and data operation deviation values, the anomaly analysis report provides detailed basis for the formulation of protective measures, promotes the transformation of detection results into protective operations, and improves the targeting of protection, such as local network anomalies causing the execution of a certain process parameter to be advanced or delayed.
[0059] Furthermore, the execution method of the anomaly response strategy specifically includes: dynamically executing any mode of the collaborative early warning instruction based on the data transmission stability of the task data stream corresponding to each task feature identifier in the anomaly correlation score, and triggering the early warning module to issue an early warning message or push the early warning message to the user terminal, thereby directly converting the anomaly analysis results into executable protection operations. Different levels of early warning modes are adapted to anomalies of varying severity, improving the timeliness, effectiveness, and flexibility of protection, and preventing the escalation of anomalies from causing greater losses. The collaborative early warning instructions include:
[0060] Low-level early warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by less than 5%, and the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to be concentrated, then a first-level early warning instruction is generated to control the data transmission link to retrieve the historical transmission record backup data of the process parameters under the corresponding detection node and send it to the execution unit to update the source data in real time, so as to remove abnormal data and keep the current process flow running normally.
[0061] Intermediate warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range of 5%-10%, and / or the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to diverge, a secondary warning instruction is generated to control the data transmission link to send a task delay response instruction to the execution unit, so that the entire process will return to normal after a delay of 3-5 seconds.
[0062] Advanced warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by 10%, and the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to be concentrated, a level 3 warning instruction will be generated to control the data transmission link to be shut down, thereby cutting off the network transmission path and preventing malicious program attacks or tampering with program running parameters.
[0063] This invention also provides a network anomaly perception and early warning system, applied to the above-mentioned method. The system includes a parameter acquisition module, an anomaly scheduling module, an anomaly analysis module, and an anomaly response module. The parameter acquisition module's data acquisition port connects to network transmission devices such as switches or industrial gateways via TCP / TP protocol, and to designated ports of execution units such as PLCs or industrial control computers via industrial bus protocol. This allows for real-time acquisition of process parameter configuration datasets from the data transmission link within a preset data detection time sequence, and normalization to construct several parameter sequences. The process parameter configuration dataset sets the initial sampling frequency of each sub-parameter based on task priority, and the initial sampling frequency of each sub-parameter is dynamically adjusted according to an anomaly pre-triggering mechanism. The anomaly pre-triggering mechanism is set as follows: when the current data change rate of any sub-parameter in the process parameter configuration dataset approaches or exceeds the anomaly pre-triggering threshold, the current sampling frequency of that sub-parameter is increased to several times the previous sampling frequency, with a value range of 0.0-1.0; when the current data change rate of any sub-parameter does not exceed the anomaly pre-triggering threshold, the sub-parameter... The current sampling frequency is restored to the initial sampling frequency; the anomaly scheduling module is used to divide several parameter sequences into several candidate groups according to the preset first and second constraints; the first constraint is: based on the process parameter configuration dataset, a number of candidate groups are set to correspond one-to-one with several task feature identifiers; the second constraint is: based on the task execution deviation set by the parameter anomaly detection range, abnormal values are retrieved from the parameter sequences, and the abnormal values are divided into the corresponding candidate groups according to the parameter sequences whose task data streams corresponding to the task feature identifiers have a similarity greater than the preset feature vector, generating several task feature identifier-abnormal data mapping tables; the anomaly analysis module analyzes the degree of abnormal correlation of parameter sequences within each candidate group, calculates the anomaly correlation score of each candidate group, and divides the candidate groups into a first-level response pool and a second-level response pool based on the anomaly correlation score; the anomaly response module, for the candidate groups in the first-level response pool, if the detection resources of each candidate group in the second-level response pool are determined, selects the remaining detection resources to trigger the perception evaluation task in combination with the anomaly correlation score; for the candidate groups in the second-level response pool, the anomaly response strategy is executed.
[0064] Furthermore, the sub-parameters of the process parameter configuration dataset in the parameter acquisition module include network parameters, target parameters, and process parameters; the target parameters are configured with multiple continuous task data streams within a preset data detection sequence according to the process execution flow, and the multiple continuous task data streams are sequentially sent to the execution unit according to the data transmission link configured by the network parameters to output the corresponding process parameters;
[0065] The anomaly analysis module is used to obtain the absolute value of the difference between the completion matching degree of all task data streams and the preset standard completion rate of the target parameters and process parameters in the same candidate group at any detection node within the current data detection time sequence, thus obtaining the process execution deviation sequence. This process execution deviation sequence is used as the key indicator of the anomaly correlation score. The anomaly correlation score is at least one of the mean and variance of the absolute values of the differences corresponding to any one or more task data streams in the process execution deviation sequence under multiple consecutive detection nodes. The mean is used to reflect whether the anomaly correlation score is within the preset monitoring threshold range. The variance is used to reflect whether the dispersion of the completion matching degree of all task data streams in the anomaly correlation score is within the preset interval. At the same time, the candidate group is divided into a primary response pool and a secondary response pool according to the grouping rules set by the scoring criteria of the anomaly correlation score.
[0066] In the above, when the anomaly response module selects remaining detection resources to trigger the perception evaluation task for the candidate group in the primary response pool, it is used to obtain the task execution deviation between the target parameter and the process parameter in any candidate group. The task execution deviation is the absolute value of the difference between the completion matching degree of the same task data stream of the target parameter and the process parameter and the preset standard completion rate. When the task execution deviation exceeds the parameter anomaly detection range of the corresponding detection node in the current data detection time sequence, the system calculates the data operation deviation values of each item in the current data transmission link based on the real-time data of the network parameters and generates a network anomaly analysis report. The data of the current data transmission link includes at least the bandwidth utilization rate and node load data.
[0067] In the above, the anomaly response module executes anomaly response strategies for candidate groups in the secondary response pool. Based on the data transmission stability of the task data stream corresponding to each task feature identifier in the anomaly association score, it dynamically executes any mode of the collaborative early warning instruction and triggers the early warning module to issue an early warning message or push the early warning message to the user terminal. The collaborative early warning instructions include:
[0068] Low-level early warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by less than 5%, and the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to be concentrated, then a first-level early warning instruction is generated to control the data transmission link to retrieve the historical transmission record backup data of the process parameters under the corresponding detection node and send it to the execution unit to update the source data in real time.
[0069] Intermediate warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range of 5%-10%, and / or the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to diverge, a secondary warning instruction is generated to control the data transmission link to send a task delay response instruction to the execution unit.
[0070] Advanced warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by 10%, and the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to be concentrated, a level 3 warning command will be generated to control the shutdown of the data transmission link.
Claims
1. A network anomaly detection and early warning method, characterized in that, Includes the following steps: Within the preset data detection time sequence, the process parameter configuration dataset of the data transmission link is collected in real time and normalized to construct several parameter sequences; The process parameter configuration dataset sets the initial sampling frequency of each sub-parameter based on task priority, and the initial sampling frequency of each sub-parameter is dynamically adjusted according to an anomaly pre-triggering mechanism. The anomaly pre-triggering mechanism is set as follows: when the current data change rate of any sub-parameter in the process parameter configuration dataset approaches or exceeds the anomaly pre-triggering threshold, the current sampling frequency of that sub-parameter is increased to several times the previous sampling frequency; when the current change rate of any sub-parameter does not exceed the anomaly pre-triggering threshold, the current sampling frequency of that sub-parameter is restored to the initial sampling frequency. Several parameter sequences are divided into several candidate groups based on a first and a second preset constraint. The first constraint is: setting a number of candidate groups that correspond one-to-one with several task feature identifiers in the process parameter configuration dataset. The second constraint is: retrieving abnormal values from the parameter sequences based on the task execution deviation set by the parameter anomaly detection range, and dividing the abnormal values into the corresponding candidate groups according to the parameter sequences whose task data streams corresponding to the task feature identifiers have a similarity greater than a preset feature vector, generating several task feature identifier-abnormal data mapping tables. Based on each candidate group, the degree of abnormal correlation of parameter sequences within the group is analyzed, the abnormal correlation score of each candidate group is calculated, and the candidate groups are divided into a first-level response pool and a second-level response pool based on the abnormal correlation score. For candidate groups in the primary response pool, if the detection resources for each candidate group in the secondary response pool are determined, the remaining detection resources are selected to trigger the perception evaluation task based on the anomaly association score. For candidate groups in the secondary response pool, execute the abnormal response strategy.
2. The network anomaly detection and early warning method according to claim 1, characterized in that, The sub-parameters of the process parameter configuration dataset include at least one of network parameters, target parameters, and process parameters; The target parameters are configured with multiple continuous task data streams within a preset data detection time sequence according to the process execution flow, and the multiple continuous task data streams are sequentially sent to the execution unit according to the data transmission link configured by the network parameters to output the corresponding process parameters.
3. The network anomaly detection and early warning method according to claim 1, characterized in that, The task priorities of the process parameter configuration dataset are set in descending order as follows: core parameters, auxiliary parameters, and redundant parameters; The core parameters include at least the data stream transmission rate and task delay response command of the process parameters, as well as the bandwidth utilization rate in the network parameters; The auxiliary parameters include at least the task feature identifier of the target parameter and the node load data of the network parameter; The redundant parameters include at least the historical transmission record backup data of the process parameters.
4. The network anomaly detection and early warning method according to claim 1, characterized in that, The method for calculating the abnormal correlation score specifically includes: The absolute value of the difference between the completion matching degree of all task data streams of the target parameters and process parameters in the same candidate group at any detection node in the current data detection time sequence and the preset standard completion rate is obtained to obtain the process execution deviation sequence. The process execution deviation sequence is used as the key indicator of the abnormal correlation score.
5. The network anomaly detection and early warning method according to claim 4, characterized in that, The anomaly correlation score is at least one of the mean and variance of the absolute values of the differences corresponding to any one or more task data streams in the process execution deviation sequence under multiple consecutive detection nodes.
6. The network anomaly detection and early warning method according to claim 1, characterized in that, The method for dividing candidate groups into a primary response pool and a secondary response pool based on anomaly correlation scores specifically includes: According to the grouping rules set by the scoring criteria of the abnormal correlation score, the candidate groups are divided into a first-level response pool and a second-level response pool; the grouping rules are as follows: the candidate groups whose abnormal correlation scores are within the preset monitoring threshold range and / or the candidate groups whose completion matching degree dispersion of all task data streams in the abnormal correlation scores is within the preset range are divided into the first-level response pool, and the remaining candidate groups are divided into the second-level response pool.
7. The network anomaly detection and early warning method according to claim 1, characterized in that, The evaluation strategy for the perception evaluation task specifically includes: Obtain the task execution deviation between the target parameter and the process parameter in any candidate group. The task execution deviation is the absolute value of the difference between the completion matching degree of the same task data stream of the target parameter and the process parameter and the preset standard completion rate. When the task execution deviation exceeds the parameter anomaly detection range of the corresponding detection node in the current data detection time sequence, calculate the data operation deviation values of each data in the current data transmission link based on the real-time data of the network parameters, and generate a network anomaly analysis report. The data for the current data transmission link includes at least bandwidth utilization and node load data.
8. The network anomaly detection and early warning method according to claim 1, characterized in that, The execution method of the aforementioned exception response strategy specifically includes: Based on the data transmission stability of the task data stream corresponding to each task feature identifier in the anomaly correlation score, any mode of the collaborative early warning instruction is dynamically executed, triggering the early warning module to issue an early warning message or push the early warning message to the user terminal. The collaborative early warning instruction includes: Low-level early warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by less than 5%, and the degree of dispersion of the completion matching degree of all task data streams in the abnormal correlation score tends to be concentrated, then a first-level early warning instruction is generated to control the data transmission link to retrieve the historical transmission record backup data of the process parameters under the corresponding detection node and send it to the execution unit to update the source data in real time. Intermediate warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range of 5%-10%, and / or the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to diverge, then a secondary warning instruction is generated to control the data transmission link to send a task delay response instruction to the execution unit. Advanced warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by 10%, and the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to be concentrated, then a level 3 warning command is generated to control the data transmission link to be shut down.
9. A network anomaly detection and early warning system, applied in the method described in any one of claims 1-8, characterized in that, The system includes: The parameter acquisition module, whose data acquisition port is connected to a designated port of the network transmission device, is used to acquire the process parameter configuration dataset of the data transmission link in real time within a preset data detection time sequence, and normalize it into several parameter sequences. The process parameter configuration dataset sets the initial sampling frequency of each sub-parameter based on task priority, and the initial sampling frequency of each sub-parameter is dynamically adjusted according to an anomaly pre-triggering mechanism. The anomaly pre-triggering mechanism is set as follows: when the current data change rate of any sub-parameter in the process parameter configuration dataset approaches or exceeds the anomaly pre-triggering threshold, the current sampling frequency of that sub-parameter is increased to several times the previous sampling frequency; when the current data change rate of any sub-parameter does not exceed the anomaly pre-triggering threshold, the current sampling frequency of that sub-parameter is restored to the initial sampling frequency. An anomaly scheduling module is used to divide a number of parameter sequences into several candidate groups based on a first constraint and a second constraint. The first constraint is to set a number of candidate groups that correspond one-to-one with several task feature identifiers in the process parameter configuration dataset. The second constraint is to retrieve abnormal values from the parameter sequences based on the task execution deviation set by the parameter anomaly detection range, and divide the abnormal values into the corresponding candidate groups according to the parameter sequences whose task data streams corresponding to the task feature identifiers have a similarity greater than a preset feature vector, generating several task feature identifier-abnormal data mapping tables. The anomaly analysis module analyzes the degree of abnormal correlation of parameter sequences within each candidate group, calculates the anomaly correlation score of each candidate group, and divides the candidate groups into a primary response pool and a secondary response pool based on the anomaly correlation score. The anomaly response module, for candidate groups in the primary response pool, if the detection resources for each candidate group in the secondary response pool are determined, combines the anomaly association score to select the remaining detection resources to trigger the perception evaluation task; for candidate groups in the secondary response pool, it executes the anomaly response strategy.
10. The network anomaly detection and early warning system according to claim 9, characterized in that, The sub-parameters of the process parameter configuration dataset in the parameter acquisition module include network parameters, target parameters, and process parameters. The target parameters are configured with multiple continuous task data streams within a preset data detection sequence according to the process execution flow, and the multiple continuous task data streams are sequentially sent to the execution unit according to the data transmission link configured by the network parameters to output the corresponding process parameters. The anomaly analysis module is used to obtain the absolute value of the difference between the completion matching degree of all task data streams of target parameters and process parameters in the same candidate group at any detection node in the current data detection time sequence and the preset standard completion rate, to obtain the process execution deviation sequence, and use the process execution deviation sequence as the key indicator of the anomaly association score; The anomaly correlation score is at least one of the mean and variance of the absolute values of the differences corresponding to any one or more task data streams in the process execution deviation sequence under multiple consecutive detection nodes; the mean is used to reflect whether the anomaly correlation score is within a preset monitoring threshold range. Variance is used to reflect whether the degree of dispersion of the completion matching of all task data streams in the anomaly association score is within a preset range; at the same time, the candidate group is divided into a primary response pool and a secondary response pool according to the grouping rules set by the scoring criteria of the anomaly association score. Specifically, when the anomaly response module selects remaining detection resources to trigger a perception evaluation task for a candidate group in the primary response pool, it obtains the task execution deviation between the target parameter and the process parameter in any candidate group. This task execution deviation is the absolute value of the difference between the completion matching degree of the same task data stream of the target parameter and the process parameter and the preset standard completion rate. When the task execution deviation exceeds the parameter anomaly detection range of the corresponding detection node within the current data detection time sequence, it calculates the data operation deviation values of each item in the current data transmission link based on real-time data of network parameters and generates a network anomaly analysis report. The data of the current data transmission link includes at least bandwidth utilization and node load data. The anomaly response module executes anomaly response strategies for candidate groups in the secondary response pool. Based on the data transmission stability of the task data stream corresponding to each task feature identifier in the anomaly association score, it dynamically executes any mode of the collaborative early warning instruction and triggers the early warning module to issue an early warning message or push the early warning message to the user terminal. The collaborative early warning instruction includes: Low-level early warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by less than 5%, and the degree of dispersion of the completion matching degree of all task data streams in the abnormal correlation score tends to be concentrated, then a first-level early warning instruction is generated to control the data transmission link to retrieve the historical transmission record backup data of the process parameters under the corresponding detection node and send it to the execution unit to update the source data in real time. Intermediate warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range of 5%-10%, and / or the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to diverge, then a secondary warning instruction is generated to control the data transmission link to send a task delay response instruction to the execution unit. Advanced warning mode: If the abnormal correlation score exceeds the preset monitoring threshold range by 10%, and the degree of dispersion of the completion matching of all task data streams in the abnormal correlation score tends to be concentrated, then a level 3 warning command is generated to control the data transmission link to be shut down.