Abnormal flow detection method, device, readable storage medium and electronic device

By using the first classification model to classify the flow segment and extract abnormal features, the misjudgment and monitoring delay problems of abnormal flow detection in the prior art are solved, and high accuracy and comprehensive abnormal flow detection are achieved.

CN113806733BActive Publication Date: 2025-05-23BEIJING WODONG TIANJUN INFORMATION TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110148678.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-02-03
Publication Date
2025-05-23
Estimated Expiration
2041-02-03

AI Technical Summary

Technical Problem

The prior art has problems such as misjudgment when detecting abnormal traffic, monitoring delay caused by attacker IP address transformation, and lack of comprehensive detection of current limiting strategies.

Method used

The first classification model is used to classify the received traffic segments into two groups, extract the abnormal traffic characteristics, and detect the abnormal traffic based on the feature set, and discard the abnormal traffic in real time.

Benefits of technology

It improves the accuracy and speed of abnormal traffic detection, can adapt to the attacker's ever-changing attack traffic characteristics, and realizes all-round detection of abnormal traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113806733B_ABST
    Figure CN113806733B_ABST
Patent Text Reader

Abstract

The embodiments of the present invention propose an abnormal traffic detection method, device, readable storage medium and electronic device. The method includes: using a first classification model to classify the received second traffic segment into two groups of traffic: a first traffic group and a second traffic group; wherein the first classification model is: calculated using a single classification algorithm for the received first traffic segment, the first traffic segment and the second traffic segment are adjacent received traffic segments, and the first traffic segment is received before the second traffic segment; extracting abnormal traffic features from the first traffic group and the second traffic group, if extracted, adding the abnormal traffic features to the abnormal traffic feature set; according to the abnormal traffic feature set, detecting whether the received traffic is abnormal traffic, if it is abnormal traffic, discarding the traffic. The embodiments of the present invention improve the accuracy and speed of abnormal traffic detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of attack detection technology, and in particular to an abnormal traffic detection method, device, readable storage medium and electronic device. Background Art

[0002] At present, there is often a large amount of abnormal traffic in online business, that is, attackers forge traffic through technical means, which not only affects the normal operation of online business, but also occupies a large amount of network transmission resources, computing resources and storage resources. If abnormal traffic can be identified in real time and accurately in actual scenarios, it can be intercepted in time, which can not only ensure the normal operation of online business, but also save resources.

[0003] Currently, the main method used is to limit the flow of traffic using IP address blacklists. That is, if a certain IP address is detected to generate traffic exceeding the threshold in a short period of time, the IP address will be added to the IP address blacklist, and then the traffic from the IP address will be intercepted according to the blacklist.

[0004] The disadvantages of the above method are as follows:

[0005] 1. In actual applications, attackers often change IP addresses to attack, which may result in: the attacker may have attacked for several hours before detecting the abnormality;

[0006] Second, the abnormal flow threshold is manually set through multiple tests, so the threshold is not necessarily accurate, resulting in misjudgment;

[0007] 3. Currently, business-based traffic limiting strategies mainly focus on IP addresses or access frequencies, and lack comprehensive detection of abnormal access. Summary of the invention

[0008] The embodiments of the present invention provide an abnormal flow detection method, an apparatus, a readable storage medium and an electronic device to improve the accuracy and speed of abnormal flow detection.

[0009] The technical solution of the embodiment of the present invention is achieved as follows:

[0010] An abnormal traffic detection method, the method comprising:

[0011] The received second flow segment is classified into two groups of flows using a first classification model: a first flow group and a second flow group; wherein the first classification model is obtained by calculating the received first flow segment using a single classification algorithm, the first flow segment and the second flow segment are adjacent received flow segments, and the first flow segment is received before the second flow segment;

[0012] Extracting abnormal traffic features from the first traffic group and the second traffic group, and if extracted, adding the abnormal traffic features to the abnormal traffic feature set;

[0013] According to the abnormal traffic feature set, it is detected whether the received traffic is abnormal traffic, and if it is abnormal traffic, the traffic is discarded.

[0014] The second traffic segment is: a set of field values ​​of each field extracted from a second interface access request set, wherein the second interface access request set is: a set of interface access requests entering the device interface in the current time period;

[0015] The first traffic segment is: a set of field values ​​of each field extracted from a first interface access request set, wherein the first interface access request set is: a set of interface access requests entering the device interface in a time period before the current time period.

[0016] The extracting of abnormal traffic features from the first traffic group and the second traffic group comprises:

[0017] Searching for a data item set whose occurrence times are greater than a preset first threshold in the first flow group and the second flow group respectively, and if found, taking the data item set as an abnormal flow feature;

[0018] Furthermore, detecting whether the received traffic is abnormal traffic according to the abnormal traffic feature set includes:

[0019] When traffic is received, it is detected whether the traffic contains any abnormal traffic feature in the abnormal traffic feature set, and if so, the traffic is determined to be abnormal traffic.

[0020] The step of searching for a set of data items with a number of occurrences greater than a preset first threshold in the first flow group and the second flow group respectively comprises:

[0021] Using a frequent item set mining method respectively, searching for frequent item sets whose support is greater than a preset first threshold in the first flow group and the second flow group;

[0022] Furthermore, the taking the data item set as an abnormal traffic feature includes:

[0023] Frequent item sets whose support is greater than a preset first threshold are taken as abnormal traffic features.

[0024] Before searching the first flow group and the second flow group for a set of data items with a number of occurrences greater than a preset first threshold, the method further includes:

[0025] Determine whether the length of the first flow group and the second flow group is less than a preset second threshold value respectively; if so, take the first flow group or the second flow group whose length is less than the preset second threshold value directly as an abnormal flow feature, and search for a set of data items whose occurrence times are greater than the preset first threshold value in the second flow group or the first flow group whose length is not less than the preset second threshold value; if neither is less than, perform the action of searching for a set of data items whose occurrence times are greater than the preset first threshold value in the first flow group and the second flow group respectively.

[0026] The adding the abnormal traffic feature to the abnormal traffic feature set further comprises:

[0027] Setting a validity period for the abnormal traffic feature;

[0028] Furthermore, when the validity period expires, the abnormal traffic feature is deleted from the abnormal traffic feature set.

[0029] An abnormal flow detection device, the device comprising:

[0030] A classification calculation module, used for classifying the received second flow segment into two groups of flows: a first flow group and a second flow group by using a first classification model; wherein the first classification model is obtained by using a single classification algorithm to calculate the received first flow segment, the first flow segment and the second flow segment are adjacent received flow segments, and the first flow segment is received before the second flow segment;

[0031] A feature extraction module, used to extract abnormal flow features from the first flow group and the second flow group, and if extracted, add the abnormal flow features to the abnormal flow feature set;

[0032] The detection module is used to detect whether the received traffic is abnormal traffic according to the abnormal traffic feature set, and if it is abnormal traffic, discard the traffic.

[0033] The feature extraction module extracts abnormal traffic features from the first traffic group and the second traffic group, including:

[0034] Determine whether the length of the first flow group and the second flow group is less than a preset second threshold value respectively; if so, directly use the first flow group or the second flow group whose length is less than the preset second threshold value as an abnormal flow feature, and search for a data item set whose appearance times are greater than the preset first threshold value in the second flow group or the first flow group whose length is not less than the preset second threshold value; if found, use the data item set as an abnormal flow feature; if neither is less than, search for a data item set whose appearance times are greater than the preset first threshold value in the first flow group and the second flow group respectively; if found, use the data item set as an abnormal flow feature;

[0035] Furthermore, the detection module detects whether the received traffic is abnormal traffic according to the abnormal traffic feature set, including:

[0036] When traffic is received, it is detected whether the traffic contains any abnormal traffic feature in the abnormal traffic feature set, and if so, the traffic is determined to be abnormal traffic.

[0037] A non-transitory computer-readable storage medium stores instructions, which, when executed by a processor, cause the processor to perform the steps of any of the above abnormal traffic detection methods.

[0038] An electronic device includes the non-transitory computer-readable storage medium as described above, and the processor capable of accessing the non-transitory computer-readable storage medium.

[0039] In an embodiment of the present invention, the second traffic segment currently received is classified based on the first classification model calculated for the most recently received first traffic segment. Since the classification model is continuously updated, the classification result can adapt to the situation where the attacker's attack traffic characteristics are constantly changing, thereby making the extracted abnormal traffic characteristics more accurate and improving the accuracy of abnormal traffic detection; moreover, there is no need for long-term monitoring, but the abnormal traffic characteristics can be extracted in real time, and the abnormal traffic detection is performed using the mentioned abnormal traffic feature set, thereby improving the speed of abnormal traffic detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative labor.

[0041] Figure 1 A flow chart of an abnormal flow detection method provided by an embodiment of the present invention;

[0042] Figure 2 A flow chart of an abnormal flow detection method provided by another embodiment of the present invention;

[0043] Figure 3 A flow chart of an abnormal flow detection method provided by another embodiment of the present invention;

[0044] Figure 4 A schematic diagram of the structure of an abnormal flow detection device provided by an embodiment of the present invention;

[0045] Figure 5 An exemplary structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0046] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0047] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein, for example. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products, or devices.

[0048] The technical solution of the present invention is described in detail with specific embodiments below. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.

[0049] The embodiment of the present invention proposes an abnormal traffic detection method, which uses a first classification model to classify the received second traffic segment into two groups of traffic: a first traffic group and a second traffic group; wherein the first classification model is: the received first traffic segment is calculated using a single classification algorithm, the first traffic segment and the second traffic segment are adjacent received traffic segments, and the first traffic segment is received before the second traffic segment; abnormal traffic features are extracted from the first traffic group and the second traffic group, and if extracted, the abnormal traffic features are added to the abnormal traffic feature set; according to the abnormal traffic feature set, it is detected whether the received traffic is abnormal traffic, and if it is abnormal traffic, the traffic entry is discarded. Through the above method, the current traffic segment is classified using the latest classification model, and because the classification model is continuously updated, the classification result can adapt to the situation where the attacker continuously changes the attack traffic features, so that the extracted abnormal traffic features are more accurate, the accuracy of abnormal traffic detection is improved, and there is no need to monitor for a long time, but the abnormal traffic features can be extracted in real time, and the abnormal traffic detection is performed using the abnormal traffic feature set mentioned above, which improves the speed of abnormal traffic detection.

[0050] Figure 1 The following is a flow chart of an abnormal flow detection method provided by an embodiment of the present invention, wherein the specific steps are as follows:

[0051] Step 101: Use the first classification model to classify the received second traffic segment into two traffic groups: a first traffic group and a second traffic group; wherein the first classification model is: calculated using a single classification algorithm for the received first traffic segment, the first traffic segment and the second traffic segment are adjacent received traffic segments, and the first traffic segment is received before the second traffic segment.

[0052] In practical applications, the second traffic segment may be: a set of field values ​​of each field extracted from a second interface access request set, wherein the second interface access request set is: a set of interface access requests from an interface entering the device in the current time period;

[0053] The first traffic segment is: a set of field values ​​of each field extracted from the first interface access request set, wherein the first interface access request set is: a set of interface access requests entering the device interface in a time period before the current time period.

[0054] All interface access requests entering the same interface of the same device must follow the same format. Interface access requests generally consist of required fields + optional fields. For each interface access request entering the interface, the values ​​of all fields are extracted from the request. If the request does not contain the value of one or some optional fields, the value of this or these optional fields is set to the default value, that is, the field values ​​of all required fields and all optional fields in each interface access request are finally obtained.

[0055] For example, an interface access request is as follows:

[0056] http: / / beta-fireclick.jd.com / adcollect.action?os=1.0.1&osVersion=5.5.0&model=mix3&lang=zh_cn&country=china&width=100&height=200&pkg=com.jd&appVersion=8.5.4&ua=1&safeReferer=1&netType=2g&carrier=dx&progress=3600&imei=e540c2fefd114c1c006b6b9ab7cdd1c6&oaid=oaid20200605wfp1&unitId=1&unitN ame=test1&clickId=2&unionId=350273051&subunionId=223344&clientType=3&clickUdt=101&adid=testk3&deeplinkUrl=http: / / ww&cal lbackUrl=https%3a%2f%2fapi.ads.heytapmobi.com%2fapi%2fuploadActiveData&platform=android&mediaId=105&clickLocationType=A.

[0057] Each "=" is preceded by a field name, and each "=" is followed by a field value. Adjacent fields are separated by "&". As you can see, the field name of the first field is "os", and the field name of the last field is "clickLocationType". You can extract the field values ​​of all fields.

[0058] The first flow section and the second flow section have the same length.

[0059] Single-classification algorithm, such as one-class SVM (Support Vector Machine) algorithm.

[0060] Step 102: extract abnormal traffic features from the first traffic group and the second traffic group. If the abnormal traffic features are extracted, add the extracted abnormal traffic features to the abnormal traffic feature set.

[0061] Step 103: According to the abnormal traffic feature set, detect whether the received traffic is abnormal traffic, and if it is abnormal traffic, discard the traffic.

[0062] The beneficial technical effects of the above embodiments are as follows:

[0063] 1. Classify the currently received second traffic segment based on the first classification model calculated for the most recently received first traffic segment. Since the classification model is continuously updated, the classification result can adapt to the situation where the attacker's attack traffic characteristics are constantly changing, so that the extracted abnormal traffic characteristics are more accurate, and the accuracy of abnormal traffic detection is improved;

[0064] Second, there is no need to monitor for a long time, but to extract abnormal traffic features in real time and add them to the abnormal traffic feature set, so that the abnormal traffic features are constantly updated and improved, and the abnormal traffic detection is performed using the abnormal traffic feature set mentioned above, which improves the accuracy and speed of abnormal traffic detection;

[0065] 3. Through the abnormal traffic characteristics, whether the received traffic is abnormal traffic is detected, thus realizing the comprehensive detection of abnormal traffic.

[0066] Figure 2 A flow chart of an abnormal flow detection method provided by another embodiment of the present invention, wherein the specific steps are as follows:

[0067] Step 201: A single classification algorithm is used to calculate the received second traffic segment to obtain a second classification model; and the first classification model is used to classify the second traffic segment into two traffic groups: a first traffic group and a second traffic group; wherein the first classification model is: the received first traffic segment is calculated using a single classification algorithm, the first traffic segment and the second traffic segment are adjacent received traffic segments, and the first traffic segment is received before the second traffic segment.

[0068] Step 202: Determine whether the length of the first flow group and the second flow group is less than the preset second threshold value respectively. If so, directly use the first flow group or the second flow group whose length is less than the preset second threshold value as the abnormal flow feature, and search for a set of data items whose occurrence times are greater than the preset first threshold value in the second flow group or the first flow group whose length is not less than the preset second threshold value. If found, use the searched set of data items as the abnormal flow feature; if neither is less than, search for a set of data items whose occurrence times are greater than the preset first threshold value in the first flow group and the second flow group respectively. If found, use the searched set of data items as the abnormal flow feature.

[0069] A data item is one field or multiple consecutive fields, and a data item set is one data item or multiple discontinuous data items.

[0070] There may be one or more data item sets whose occurrence times are greater than a preset first threshold, and each of them serves as an abnormal traffic feature.

[0071] If the lengths of the first flow group and the second flow group are both greater than the preset second threshold, and a set of data items whose occurrence times are greater than the preset first threshold are not searched in the first flow group and the second flow group, then it means that there are no abnormal flow features in the first flow group and the second flow group.

[0072] In practical applications, in this step, searching for a set of data items with a number of occurrences greater than a preset first threshold in the first flow group and the second flow group respectively may include:

[0073] Frequent item set mining methods such as FP-Growth (Frequent-Pattern Growth) are respectively used to search for frequent item sets whose support is greater than a preset first threshold in the first traffic group and the second traffic group; and, if found, the frequent item sets whose support is greater than the preset first threshold are used as abnormal traffic features.

[0074] Step 203: Add the abnormal traffic feature to the abnormal traffic feature set.

[0075] Step 204: When traffic is received, detect whether the traffic contains any abnormal traffic feature in the abnormal traffic feature set. If so, determine that the traffic is abnormal traffic and discard the traffic; otherwise, accept the traffic.

[0076] In the above embodiment, by respectively judging whether the length of the first flow group and the second flow group is less than the preset second threshold value, if so, the first flow group or the second flow group whose length is less than the preset second threshold value is directly used as the abnormal flow feature, and searching for a set of data items whose occurrence times are greater than the preset first threshold value in the second flow group or the first flow group whose length is not less than the preset second threshold value, if found, the searched set of data items is used as the abnormal flow feature; if neither is less than, searching for a set of data items whose occurrence times are greater than the preset first threshold value in the first flow group and the second flow group respectively, if found, the searched set of data items is used as the abnormal flow feature, thereby realizing real-time extraction of abnormal flow features.

[0077] In practical applications, considering the continuous changes in abnormal traffic characteristics, in order to ensure the reliability of abnormal traffic detection, the following optimization scheme is given:

[0078] In step 102 or step 203, when the abnormal traffic feature is added to the abnormal traffic feature set, a validity period is set for the abnormal traffic feature; and when the validity period expires, the abnormal traffic feature is deleted from the abnormal traffic feature set.

[0079] In the above embodiment, on the basis of ensuring the continuous updating of abnormal traffic characteristics, invalid abnormal traffic characteristics are deleted in time, thereby ensuring the reliability of abnormal traffic detection.

[0080] The following are application examples of the present invention:

[0081] Figure 3 A flow chart of an abnormal flow detection method provided by another embodiment of the present invention, wherein the specific steps are as follows:

[0082] Step 301: For each flow of a preset length, such as 5 seconds, entering from the first interface of the device (the flow consists of multiple interface access requests entering the first interface), perform the following steps 302-307:

[0083] Step 302: extract the field value of each field from each interface access request of the traffic, and concatenate the field values ​​of all the extracted fields to obtain a second traffic segment.

[0084] If any interface access request does not contain one or some fields, the values ​​of the one or some fields are replaced by default values.

[0085] Step 303: Perform the following two processing steps on the second flow segment:

[0086] Process 1: Use one-class SVM to calculate the second traffic segment and obtain the second classification kernel function;

[0087] The second classification kernel function is used to classify the traffic entering the first interface in the next 5 seconds.

[0088] Process 2: Use the first classification kernel function to classify the second flow segment, and divide the second flow segment into two groups: a first flow group and a second flow group.

[0089] Among them, the first classification kernel function is obtained by performing one-class SVM calculation on the traffic in the previous 5 seconds entering the first interface. Therefore, when it is used to classify the second traffic segment, the accuracy of the classification result cannot be guaranteed. Therefore, when performing subsequent abnormal traffic feature extraction, both the first traffic group and the second traffic group must participate.

[0090] Step 304: Determine whether the length of the first flow group and the length of the second flow group are less than a preset second threshold respectively. If so, execute step 305; otherwise, execute step 306.

[0091] The value of the second threshold is less than half the length of the second flow segment, and the specific value can be determined based on experience or the like.

[0092] Step 305: Take the first traffic group or the second traffic group whose length is less than the preset second threshold as the abnormal traffic feature; and use the FP-Growth algorithm to mine frequent item sets for the second traffic group or the first traffic group whose length is not less than the preset second threshold. If a frequent item set with a support greater than the preset first threshold (such as 100) is mined, the frequent item set is taken as the abnormal traffic feature; go to step 307.

[0093] At most, only one of the first flow group and the second flow group may have a length smaller than the preset second threshold.

[0094] When the length of the first flow group or the second flow group is less than the preset second threshold, it means that the distinction between the first flow group and the second flow group is large, and the classification result of the first classification kernel function can be trusted, then the first flow group or the second flow group whose length is less than the preset second threshold is directly used as an abnormal flow feature.

[0095] Step 306: Use the FP-Growth algorithm to mine frequent itemsets for the first traffic group and the second traffic group respectively. If a frequent item set with a support greater than a preset first threshold (eg, 100) is mined, the frequent item set is used as an abnormal traffic feature.

[0096] In this step, if no frequent item set with a support greater than a preset first threshold is mined, it is determined that both the first traffic group and the second traffic group are legitimate traffic.

[0097] Step 307: adding each abnormal traffic feature to the abnormal traffic feature set of the first interface.

[0098] When each abnormal flow feature is added to the abnormal flow feature set, an aging timer will be started for the abnormal flow feature, and the timing duration is equal to the preset validity period. When the timer expires, the abnormal flow feature will be deleted from the abnormal flow feature set.

[0099] Step 308: When any interface access request is received from the first interface, check whether any abnormal traffic feature in the abnormal traffic feature set exists in the request. If so, determine that the request is abnormal traffic and prohibit the request from entering the first interface; otherwise, allow the request to enter the first interface.

[0100] The applicant needs to explain that, during the daily monitoring process, the inventors found that the access of the brush volume devices usually presents a periodic pattern, so the following will occur: the data in some time windows are all brush volume access, the data in some time windows are all normal access, and the data in some windows are both brush volume devices and normal access. The abnormal traffic detection method provided in the embodiment of the present invention can adapt to the continuous changes of abnormal traffic characteristics because the abnormal traffic characteristics are continuously extracted and updated, and can achieve good detection effects for the above-mentioned situations.

[0101] Figure 4 A schematic diagram of the structure of an abnormal flow detection device provided by an embodiment of the present invention, the device mainly comprises:

[0102] The classification calculation module 41 is used to use the first classification model to classify the received second traffic segment into two groups of traffic: a first traffic group and a second traffic group; wherein the first classification model is: the received first traffic segment is calculated using a single classification algorithm, the first traffic segment and the second traffic segment are adjacent received traffic segments, and the first traffic segment is received before the second traffic segment.

[0103] The feature extraction module 42 is used to extract abnormal flow features from the first flow group and the second flow group classified by the classification calculation module 41. If the abnormal flow features are extracted, the abnormal flow features are added to the abnormal flow feature set.

[0104] The detection module 43 is used to detect whether the received traffic is abnormal traffic based on the abnormal traffic feature set obtained by the feature extraction module 42, and if it is abnormal traffic, discard the traffic.

[0105] In an optional embodiment, the second traffic segment is: a set of field values ​​of each field extracted from the second interface access request set, wherein the second interface access request set is: a set of interface access requests entering the device interface in the current time period;

[0106] The first traffic segment is: a set of field values ​​of each field extracted from the first interface access request set, wherein the first interface access request set is: a set of interface access requests entering the device interface in a time period before the current time period.

[0107] In an optional embodiment, the feature extraction module 42 extracts the abnormal traffic feature from the first traffic group and the second traffic group, including: searching for a set of data items whose occurrence times are greater than a preset first threshold in the first traffic group and the second traffic group respectively, and if found, using the searched set of data items as the abnormal traffic feature;

[0108] Furthermore, the detection module 43 detects whether the received traffic is abnormal traffic based on the abnormal traffic feature set, including: when receiving traffic, detecting whether the traffic contains any abnormal traffic feature in the abnormal traffic feature set, and, if so, determining that the traffic is abnormal traffic.

[0109] In an optional embodiment, the feature extraction module 42 searches for a set of data items with a number of occurrences greater than a preset first threshold in the first flow group and the second flow group respectively, including: using a frequent item set mining method respectively to search for frequent item sets with a support greater than a preset first threshold in the first flow group and the second flow group;

[0110] Furthermore, the feature extraction module 42 uses the searched data item set as the abnormal traffic feature, including: using the frequent item set with support greater than a preset first threshold as the abnormal traffic feature.

[0111] In an optional embodiment, before the feature extraction module 42 searches for a set of data items whose occurrence times are greater than a preset first threshold in the first flow group and the second flow group respectively, it is further configured to:

[0112] Determine whether the length of the first flow group and the second flow group is less than a preset second threshold value respectively; if so, take the first flow group or the second flow group whose length is less than the preset second threshold value directly as an abnormal flow feature, and search for a set of data items whose occurrence times are greater than the preset first threshold value in the second flow group or the first flow group whose length is not less than the preset second threshold value; if neither is less than, perform the action of searching for a set of data items whose occurrence times are greater than the preset first threshold value in the first flow group and the second flow group respectively.

[0113] In an optional embodiment, the feature extraction module 42 adds the abnormal traffic feature to the abnormal traffic feature set, further comprising: setting a validity period for the abnormal traffic feature; and, when the validity period expires, deleting the abnormal traffic feature from the abnormal traffic feature set.

[0114] The embodiment of the present application also provides a computer-readable storage medium, which stores instructions, and when the instructions are executed by a processor, the steps in the implementation method of abnormal traffic detection as described above can be executed. In practical applications, the computer-readable medium can be included in each device / apparatus / system in the above embodiments, or it can exist independently without being assembled into the device / apparatus / system. Instructions are stored in a computer-readable storage medium, and when the instructions stored therein are executed by a processor, the steps in the abnormal traffic detection method as described above can be executed.

[0115] According to the embodiments disclosed in the present application, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof, but it is not used to limit the scope of protection of the present application. In the embodiments disclosed in the present application, the computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, apparatus, or device.

[0116] like Figure 5 As shown, an embodiment of the present invention also provides an electronic device. Figure 5 As shown, it shows a schematic diagram of the structure of an electronic device involved in an embodiment of the present invention, specifically:

[0117] The electronic device may include a processor 51 with one or more processing cores, a memory 52 with one or more computer-readable storage media, and a computer program stored in the memory and executable on the processor. When executing the program in the memory 52, the above-mentioned method for detecting abnormal traffic flow may be implemented.

[0118] Specifically, in practical applications, the electronic device may further include components such as a power supply 53, an input / output unit 54, etc. Those skilled in the art may understand that Figure 5 The structure of the electronic device shown in the figure does not constitute a limitation on the electronic device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0119] The processor 51 is the control center of the electronic device. It uses various interfaces and lines to connect various parts of the entire electronic device. It executes various functions of the server and processes data by running or executing software programs and / or modules stored in the memory 52 and calling data stored in the memory 52, thereby monitoring the electronic device as a whole.

[0120] The memory 52 can be used to store software programs and modules, that is, the above-mentioned computer-readable storage medium. The processor 51 executes various functional applications and data processing by running the software programs and modules stored in the memory 52. ​​The memory 52 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function, etc.; the data storage area may store data created according to the use of the server, etc. In addition, the memory 52 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices. Accordingly, the memory 52 may also include a memory controller to provide the processor 51 with access to the memory 52.

[0121] The electronic device also includes a power supply 53 for supplying power to various components, which can be logically connected to the processor 51 through a power management system, so as to manage charging, discharging, power consumption and other functions through the power management system. The power supply 53 can also include one or more DC or AC power supplies, recharging systems, power failure detection circuits, power converters or inverters, power status indicators and other arbitrary components.

[0122] The electronic device may further include an input-output unit 54, which may be used to receive input digital or character information and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function control. The input-output unit 54 may also be used to display information input by the user or information provided to the user and various graphical user interfaces, which may be composed of graphics, text, icons, videos and any combination thereof.

[0123] The flow chart and block diagram in the accompanying drawings of the present application show the possible architecture, function and operation of the system, method and computer program product according to the various embodiments disclosed in the present application. In this regard, each box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the above-mentioned module, program segment or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the box can also occur in the order of the standards in different figures. For example, the boxes represented by two connections can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0124] Those skilled in the art will appreciate that the features described in the various embodiments and / or claims of the present disclosure may be combined and / or combined in a variety of ways, even if such combinations or combinations are not explicitly described in the present application. In particular, without departing from the spirit and teachings of the present application, the features described in the various embodiments and / or claims of the present application may be combined and / or combined in a variety of ways, and all of these combinations and / or combinations fall within the scope disclosed in the present application.

[0125] Specific embodiments are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas, and is not used to limit the present application. For those skilled in the art, changes can be made in the specific implementation methods and application scopes according to the ideas, spirits and principles of the present invention, and any modifications, equivalent substitutions, improvements, etc. made therein should be included in the scope of protection of this application.

Claims

1. A method for detecting abnormal traffic. It is characterized in that The method includes: The received second flow segment is classified into two groups of flows using a first classification model: a first flow group and a second flow group; wherein the first classification model is obtained by calculating the received first flow segment using a single classification algorithm, the first flow segment and the second flow segment are adjacent received flow segments, and the first flow segment is received before the second flow segment; Extracting abnormal traffic features from the first traffic group and the second traffic group, and if extracted, adding the abnormal traffic features to the abnormal traffic feature set; Detecting whether the received traffic is abnormal traffic according to the abnormal traffic feature set, and if it is abnormal traffic, discarding the traffic; The extracting of abnormal traffic features from the first traffic group and the second traffic group comprises: Searching for a data item set whose occurrence times are greater than a preset first threshold in the first flow group and the second flow group respectively, and if found, taking the data item set as an abnormal flow feature; Before searching the first flow group and the second flow group for a set of data items with a number of occurrences greater than a preset first threshold, the method further includes: Determine whether the length of the first flow group and the second flow group is less than the preset second threshold value respectively. If so, take the first flow group or the second flow group whose length is less than the preset second threshold value directly as the abnormal flow feature, and search for a set of data items whose occurrence times are greater than the preset first threshold value in the second flow group or the first flow group whose length is not less than the preset second threshold value.

2. The method according to claim 1, It is characterized in that The second traffic segment is: a set of field values ​​of each field extracted from a second interface access request set, wherein the second interface access request set is: a set of interface access requests entering the device interface in the current time period; The first traffic segment is: a set of field values ​​of each field extracted from a first interface access request set, wherein the first interface access request set is: a set of interface access requests entering the device interface in a time period before the current time period.

3. The method according to claim 1, It is characterized in that The detecting, according to the abnormal traffic feature set, whether the received traffic is abnormal traffic includes: When traffic is received, it is detected whether the traffic contains any abnormal traffic feature in the abnormal traffic feature set, and if so, the traffic is determined to be abnormal traffic.

4. The method according to claim 1, It is characterized in that The step of searching for a set of data items with a number of occurrences greater than a preset first threshold in the first flow group and the second flow group respectively comprises: Using a frequent item set mining method respectively, searching for frequent item sets whose support is greater than a preset first threshold in the first flow group and the second flow group; Furthermore, the taking the data item set as an abnormal traffic feature includes: Frequent item sets whose support is greater than a preset first threshold are taken as abnormal traffic features.

5. The method according to claim 1 or 4, It is characterized in that Before searching the first flow group and the second flow group for a set of data items with a number of occurrences greater than a preset first threshold, the method further includes: If neither is less than, the action of searching the first flow group and the second flow group for a set of data items whose occurrence times are greater than a preset first threshold is performed.

6. The method according to claim 1, It is characterized in that The adding the abnormal traffic feature to the abnormal traffic feature set further comprises: Setting a validity period for the abnormal traffic feature; Furthermore, when the validity period expires, the abnormal traffic feature is deleted from the abnormal traffic feature set.

7. An abnormal flow detection device, It is characterized in that The device includes: A classification calculation module, used for classifying the received second flow segment into two groups of flows: a first flow group and a second flow group by using a first classification model; wherein the first classification model is obtained by using a single classification algorithm to calculate the received first flow segment, the first flow segment and the second flow segment are adjacent received flow segments, and the first flow segment is received before the second flow segment; A feature extraction module, used to extract abnormal flow features from the first flow group and the second flow group, and if extracted, add the abnormal flow features to the abnormal flow feature set; A detection module, used to detect whether the received traffic is abnormal traffic according to the abnormal traffic feature set, and if it is abnormal traffic, discard the traffic; The feature extraction module extracts abnormal traffic features from the first traffic group and the second traffic group, including: Searching for a data item set whose occurrence times are greater than a preset first threshold in the first flow group and the second flow group respectively, and if found, taking the data item set as an abnormal flow feature; Before the feature extraction module searches for a set of data items with a number of occurrences greater than a preset first threshold in the first flow group and the second flow group respectively, the feature extraction module is further used to: Determine whether the length of the first flow group and the second flow group is less than the preset second threshold value respectively. If so, take the first flow group or the second flow group whose length is less than the preset second threshold value directly as the abnormal flow feature, and search for a set of data items whose occurrence times are greater than the preset first threshold value in the second flow group or the first flow group whose length is not less than the preset second threshold value.

8. The device according to claim 7, It is characterized in that Before the feature extraction module extracts abnormal flow features from the first flow group and the second flow group, the feature extraction module is further used to: If neither is less than, searching the first flow group and the second flow group for a data item set whose occurrence times are greater than a preset first threshold respectively, and if found, taking the data item set as an abnormal flow feature; Furthermore, the detection module detects whether the received traffic is abnormal traffic according to the abnormal traffic feature set, including: When traffic is received, it is detected whether the traffic contains any abnormal traffic feature in the abnormal traffic feature set, and if so, the traffic is determined to be abnormal traffic.

9. A non-transitory computer-readable storage medium storing instructions, It is characterized in that When the instructions are executed by a processor, the processor is caused to perform the steps of the abnormal traffic detection method according to any one of claims 1 to 6.

10. An electronic device, It is characterized in that The method comprises the non-transitory computer-readable storage medium of claim 9, and the processor having access to the non-transitory computer-readable storage medium.

Citation Information

Patent Citations

  • Network abnormal behavior detection and analysis method and system

    CN107426199A

  • Network traffic anomaly detection method, apparatus, computer device and storage medium

    WO2019095719A1