A network intrusion detection method, device, equipment and storage medium

By optimizing the sorting of data filtering and network intrusion detection rules, the problems of large consumption and low efficiency of network intrusion detection resources in the prior art are solved, and a more efficient detection process is achieved.

CN114765556BActive Publication Date: 2025-06-13TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110044969.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-13
Publication Date
2025-06-13
Estimated Expiration
2041-01-13

AI Technical Summary

Technical Problem

The use of a large number of detection rules in network intrusion detection results in large system resource consumption and low detection efficiency.

Method used

By obtaining the traffic to be detected, sorting based on a variety of data filtering strategies and network intrusion detection rules, the data filtering and detection process is optimized, thereby reducing system resource consumption and improving detection efficiency.

Benefits of technology

It effectively reduces system resource consumption, greatly improves network intrusion detection efficiency, and does not require hardware upgrades, reducing costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114765556B_ABST
    Figure CN114765556B_ABST
Patent Text Reader

Abstract

The present application discloses a network intrusion detection method, device, equipment and storage medium. The method includes: obtaining traffic to be detected; performing data filtering on the traffic to be detected based on a variety of data filtering policies and filtering sorting information of the variety of data filtering policies to obtain filtered traffic data; the filtering sorting information is determined based on system resource consumption and / or filtering performance corresponding to filtering the preset traffic respectively by the variety of data filtering policies, performing network intrusion detection on the filtered traffic data based on a variety of network intrusion detection rules and detection sorting information to obtain a target intrusion detection result; the detection sorting information is determined based on system resource consumption and / or detection performance corresponding to performing network intrusion detection on the preset traffic respectively by the variety of network intrusion detection rules. By using the technical solution provided by the embodiments of the present application, the system resource consumption can be effectively reduced and the network intrusion detection efficiency can be greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet communication technologies, and in particular, to a network intrusion detection method, apparatus, device, and storage medium. Background Art

[0002] With the development of the Internet, the network intrusions faced by a large number of Internet systems have become more and more diverse, resulting in the need for a large number of network intrusion detection rules for detection. However, using a large number of network intrusion detection rules for network intrusion detection brings problems of high system resource consumption and detection efficiency. Therefore, a more reliable or efficient solution is needed. Summary of the Invention

[0003] The present application provides a network intrusion detection method, apparatus, device, and storage medium, which can effectively reduce system resource consumption and greatly improve network intrusion detection efficiency.

[0004] On the one hand, the present application provides a network intrusion detection method, the method comprising:

[0005] Obtaining traffic to be detected;

[0006] Performing data filtering on the traffic to be detected based on a plurality of data filtering policies and filtering sorting information of the plurality of data filtering policies to obtain filtered traffic data; the filtering sorting information is determined based on system resource consumption and / or filtering performance corresponding to filtering the preset traffic by the plurality of data filtering policies respectively;

[0007] Determining a plurality of network intrusion detection rules corresponding to the traffic to be detected and detection sorting information of the plurality of network intrusion detection rules, the detection sorting information being determined based on system resource consumption and / or detection performance corresponding to performing network intrusion detection on the preset traffic by the plurality of network intrusion detection rules respectively;

[0008] Performing network intrusion detection on the filtered traffic data based on the plurality of network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result.

[0009] On the other hand, a network intrusion detection apparatus is provided, the apparatus comprising:

[0010] A traffic-to-be-detected acquisition module, configured to obtain traffic to be detected;

[0011] A first data filtering module, configured to perform data filtering on the traffic to be detected based on a plurality of data filtering policies and filtering sorting information of the plurality of data filtering policies to obtain filtered traffic data; the filtering sorting information is determined based on system resource consumption and / or filtering performance corresponding to filtering the preset traffic by the plurality of data filtering policies respectively;

[0012] A data determination module, configured to determine a variety of network intrusion detection rules corresponding to the traffic to be detected and detection sorting information of the variety of network intrusion detection rules, where the detection sorting information is determined based on system resource consumption and / or detection performance corresponding to performing network intrusion detection on preset traffic by the variety of network intrusion detection rules respectively;

[0013] A first network intrusion detection module, configured to perform network intrusion detection on the filtered traffic data based on the variety of network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result.

[0014] On the other hand, a network intrusion detection device is provided, where the device includes a processor and a memory, and at least one instruction or at least one program segment is stored in the memory, and the at least one instruction or the at least one program segment is loaded and executed by the processor to implement the network intrusion detection method as described above.

[0015] On the other hand, a computer-readable storage medium is provided, where at least one instruction or at least one program segment is stored in the storage medium, and the at least one instruction or the at least one program segment is loaded and executed by a processor to implement the network intrusion detection method as described above.

[0016] The network intrusion detection method, device, equipment and storage medium provided by this application have the following technical effects:

[0017] When performing network intrusion detection on the traffic to be detected in this application, first, in combination with the filtering sorting information determined based on the system resource consumption and / or filtering performance corresponding to filtering preset traffic by a variety of data filtering strategies respectively, it is possible to fully consider the impact of different sorts of a variety of data filtering strategies on data filtering efficiency and system performance, greatly improving data filtering efficiency, and by pre-filtering the traffic to be detected, the amount of data processed during subsequent network intrusion detection can be effectively reduced; then, in combination with the detection sorting information determined based on the system resource consumption and / or detection performance corresponding to performing network intrusion detection on preset traffic by a variety of network intrusion detection rules respectively, it is possible to effectively consider the impact of different sorts of a variety of network intrusion detection rules on network intrusion detection efficiency and system performance, thereby effectively reducing system resource consumption and greatly improving network intrusion detection efficiency. Description of the Drawings

[0018] In order to more clearly illustrate the technical solutions and advantages in the embodiments of this application or the prior art, the following will briefly introduce the drawings required for description in the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0019] Figure 1 is a schematic diagram of an application environment provided by an embodiment of the present application;

[0020] Figure 2 is a schematic flowchart of a network intrusion detection method provided by an embodiment of the present application;

[0021] Figure 3 is a schematic flowchart of a network intrusion detection method provided by an embodiment of the present application;

[0022] Figure 4 is a schematic flowchart of a process for pre - determining filtering and sorting information provided by an embodiment of the present application;

[0023] Figure 5 is another schematic flowchart of a process for pre - determining filtering and sorting information provided by an embodiment of the present application;

[0024] Figure 6 is a schematic diagram of mapping a detection application to network intrusion detection rules provided by an embodiment of the present application;

[0025] Figure 7 is a schematic flowchart of a process for pre - determining detection sorting information provided by an embodiment of the present application;

[0026] Figure 8 is another schematic flowchart of a process for pre - determining detection sorting information provided by an embodiment of the present application;

[0027] Figure 9 is a schematic flowchart of another network intrusion detection method provided by an embodiment of the present application;

[0028] Figure 10 is a schematic flowchart of another network intrusion detection method provided by an embodiment of the present application;

[0029] Figure 11 is a schematic structural diagram of a network intrusion detection device provided by an embodiment of the present application;

[0030] Figure 12 is a hardware structure block diagram of a server for implementing the network intrusion detection method provided by an embodiment of the present application. Detailed implementation manners

[0031] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0032] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of this application are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or devices.

[0033] Please refer to Figure 1 , Figure 1 which is a schematic diagram of an application environment provided by an embodiment of this application. As Figure 1 shown, the application environment may include a client 01, a core switch 02, a gateway 03, a server 04, a mirror switch 05, and a network intrusion detection system 06.

[0034] In actual application, when the client 01 sends a network request (i.e., traffic) to the server 04 through the Internet, it will first connect to the server 04 through the path constructed by the core switch 02 and the gateway 03 in sequence.

[0035] In the embodiments of this specification, the client 01 includes types of electronic devices such as smart phones, desktop computers, tablet computers, laptop computers, smart speakers, digital assistants, augmented reality (AR) / virtual reality (VR) devices, and smart wearable devices. It may also include software running on the above-mentioned electronic devices.

[0036] In the embodiments of this specification, the core switch 02 may include, but is not limited to, an Ethernet switch, a fiber switch, etc.

[0037] In the embodiments of this specification, the gateway 03 may include, but is not limited to, an Internet gateway, a LAN gateway.

[0038] In the embodiments of this specification, the server 04 may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It may also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.

[0039] In the embodiments of this specification, the mirror switch 05 can be used to copy traffic from the core switch 02; specifically, the mirror switch 05 can include, but is not limited to, an Ethernet switch, a fiber switch, etc.

[0040] In the embodiments of this specification, the network intrusion detection system 06 can be used to perform network intrusion detection on the traffic copied by the mirror switch 05.

[0041] In addition, it should be noted that the connection and communication between the above-mentioned client and server are not limited to the above-mentioned wireless network method, and can also be connected by wire, and this application does not make any restrictions here.

[0042] The following introduces a network intrusion detection method of this application. Figure 2 It is a flowchart of a network intrusion detection method provided by the embodiments of this application. This specification provides the method operation steps as described in the embodiments or flowcharts, but based on routine or non-creative labor, there may be more or fewer operation steps. The step order listed in the embodiments is only one way among the execution orders of numerous steps, and does not represent the only execution order. When the actual system or server product executes, it can be executed in the order of the embodiments or as shown in the drawings, or executed in parallel (for example, in an environment of parallel processors or multi-threaded processing). Specifically, as Figure 2 shown, the method may include:

[0043] S201: Obtain the traffic to be detected.

[0044] In the embodiments of this specification, the traffic to be detected may include network requests to be detected, such as HTTP requests. In a specific embodiment, obtaining the traffic to be detected may include: copying the traffic on the core switch; using the copied traffic as the above-mentioned traffic to be detected.

[0045] S203: Perform data filtering on the traffic to be detected based on multiple data filtering policies and the filtering sorting information of the multiple data filtering policies to obtain filtered traffic data.

[0046] In an optional embodiment, before performing data filtering on the traffic to be detected based on multiple data filtering policies and the filtering sorting information of the multiple data filtering policies to obtain filtered traffic data, as Figure 3 shown, the above method may further include:

[0047] S209: Obtain the multiple data filtering policies and the filtering sorting information of the multiple data filtering policies;

[0048] In the embodiments of this specification, in order to improve the efficiency of network intrusion detection and the consumption of system resources, data filtering can be performed on the traffic to be detected before intrusion detection to filter out some data that does not need to be detected. In practical applications, the types of data that do not need to be detected are diverse, and different data filtering strategies often need to be combined for data filtering. In the embodiments of this specification, the filtering sorting information is determined based on the system resource consumption and / or filtering performance corresponding to filtering the preset traffic using the multiple data filtering strategies respectively.

[0049] In a specific embodiment, the above method may further include the step of pre-determining the filtering sorting information. Optionally, as Figure 4 shown, pre-determining the filtering sorting information may include:

[0050] S401: Obtain the preset traffic;

[0051] S403: Perform data filtering on the preset traffic using the multiple data filtering strategies respectively to obtain the filtering results corresponding to each data filtering strategy;

[0052] S405: Use the system resource consumption parameters generated during the filtering of the preset traffic by each data filtering strategy as the system resource consumption parameters corresponding to each data filtering strategy;

[0053] S407: Determine the filtering parameters corresponding to each data filtering strategy based on the filtering results corresponding to the multiple data filtering strategies;

[0054] S409: Determine the filtering sorting information of the multiple data filtering strategies according to the filtering parameters and / or system resource consumption parameters corresponding to the multiple data filtering strategies.

[0055] In a specific embodiment, the multiple data filtering strategies may include, but are not limited to, at least two of a static domain name filtering strategy, a static CGI (Common Gateway Interface) filtering strategy, a scanner filtering strategy, and an invisible encoding filtering strategy.

[0056] In practical applications, static resources are usually stored using a separate domain name. General static resources are placed on a CDN (Content Delivery Network). Usually, normal services do not run on the CDN. Therefore, network intrusion detection is not required for this part of the traffic. Correspondingly, filtering out this part of the traffic will greatly reduce the system resource consumption and detection efficiency during the network intrusion detection process. Correspondingly, in the embodiments of this specification, the static domain name filtering policy may include a policy of removing the CDN domain name contained in the traffic to be detected. In the embodiments of this specification, static resources may include, but are not limited to, pictures, videos, audios, compressed package static files, etc.

[0057] In practical applications, not all static resources are placed on the CDN domain name. Therefore, other policies are also needed to filter static resources. Generally, the request CGIs of static resources usually appear in a specific form, such as.js,.css,.mp4,.png,.rar,.zip, etc. Therefore, by filtering the traffic to be detected that includes these CGIs in a specific form, the system resource consumption and detection efficiency during the network intrusion detection process can be greatly reduced. Correspondingly, in the embodiments of this specification, the static CGI filtering policy may include a policy of removing the static CGL contained in the traffic to be detected. Specifically, static CGIs may include, but are not limited to, CGIs in forms such as.js,.css,.mp4,.png,.rar,.zip, etc.

[0058] In practical applications, some enterprises often use scanners to conduct regular detection scans on their own first. There is often a large amount of such scanning and detection traffic, resulting in a waste of resource consumption, and it will not be blocked by the enterprise firewall (the enterprise's own scanner is safe and controllable, and blocking it will prevent normal use). Moreover, this part of the traffic will cause a large number of attack alarms, affecting the operation efficiency. Correspondingly, in the embodiments of this specification, the scanner filtering policy may include a policy of removing the scanning and detection traffic generated by the scanner in the traffic to be detected.

[0059] In practical applications, there is a lot of encrypted traffic and binary file upload traffic in the traffic to be detected. This part of the traffic belongs to invisible encoding. Therefore, removing this part of the traffic has no impact on network intrusion detection, but can reduce the system resource consumption and detection efficiency during the network intrusion detection process. Correspondingly, in the embodiments of this specification, the invisible encoding filtering policy may include a policy of removing encrypted traffic and binary file upload traffic in the traffic to be detected.

[0060] In practical applications, when different data filtering strategies are used for data filtering, the system resource consumption and filtering performance are often different. Specifically, the system resource consumption can be reflected by system resource consumption parameters such as, but not limited to, the CPU consumption (in Hertz) and the proportion of the consumed CPU. The filtering performance can be reflected by filtering performance parameters such as, but not limited to, the proportion of the filtered traffic in the total traffic. In practical applications, the traffic to be detected can be obtained at a certain frequency, or the operation of obtaining the traffic to be detected can be triggered in combination with the actual application requirements. The above traffic to be detected can include multiple network requests. Optionally, the total traffic can be the number of network requests in the traffic to be detected. Correspondingly, the traffic filtered by a certain data filtering strategy can be the number of network requests in the filtered traffic.

[0061] In an optional embodiment, when determining the filtering sorting information of the multiple data filtering strategies according to the filtering parameters corresponding to the multiple data filtering strategies, the multiple data filtering strategies can be sorted in descending order according to the numerical values of the filtering parameters corresponding to the multiple data filtering strategies to obtain the filtering sorting information.

[0062] In the above embodiment, by combining the numerical values of the filtering parameters corresponding to the data filtering strategies and sorting the multiple data filtering strategies in descending order according to the numerical values to obtain the filtering sorting information, the data filtering can be preferentially performed by the data filtering strategy that can filter out more traffic. Correspondingly, the subsequent data filtering strategies can filter less traffic, thereby reducing the system resource consumption and greatly improving the data filtering efficiency.

[0063] In a specific embodiment, when determining the filtering sorting information of the multiple data filtering strategies according to the system resource consumption parameters corresponding to the multiple data filtering strategies, the multiple data filtering strategies can be sorted in ascending order according to the numerical values of the system resource consumption parameters corresponding to the multiple data filtering strategies to obtain the filtering sorting information.

[0064] In the above embodiment, by combining the numerical values of the system resource consumption parameters corresponding to the data filtering strategies and sorting the multiple data filtering strategies in ascending order according to the numerical values to obtain the filtering sorting information, less system performance can be consumed in the early stage, and at the same time, a part of the traffic belonging to network intrusion can be detected first, so that the subsequent data filtering strategies with larger system resource consumption can filter less traffic, thereby reducing the system resource consumption and improving the data filtering efficiency.

[0065] In the case of determining the filtering sorting information of the multiple data filtering policies based on the filtering parameters and system resource consumption parameters corresponding to the multiple data filtering policies, the third weight corresponding to the filtering parameters and the fourth weight corresponding to the system resource consumption parameters can be determined, and the filtering parameters and system resource consumption parameters corresponding to each data filtering policy are weighted based on the third weight and the fourth weight to obtain weighted filtering parameters; the multiple data filtering policies are sorted according to the numerical magnitudes of the weighted filtering parameters to obtain the filtering sorting information.

[0066] In the embodiments of the present specification, the signs of the third weight and the fourth weight can be opposite, the sum of the absolute values of the third weight and the fourth weight can be 1, and the specific numerical values of the third weight and the fourth weight can be set in advance in combination with actual applications. In a specific embodiment, for example, the absolute value of the third weight is 0.95 and the absolute value of the fourth weight is 0.05. Optionally, when the third weight is positive and the fourth weight is negative, sorting the multiple data filtering policies according to the numerical magnitudes of the weighted filtering parameters to obtain the filtering sorting information can include sorting the multiple data filtering policies from largest to smallest according to the numerical magnitudes of the weighted filtering parameters to obtain the filtering sorting information. Conversely, when the third weight is negative and the fourth weight is positive, sorting the multiple data filtering policies according to the numerical magnitudes of the weighted filtering parameters to obtain the filtering sorting information can include sorting the multiple data filtering policies from smallest to largest according to the numerical magnitudes of the weighted filtering parameters to obtain the filtering sorting information.

[0067] Optionally, when the filtering parameters and the system resource consumption parameters do not belong to data of the same order of magnitude, for example, the system resource consumption parameter is the cup consumption; the filtering performance parameter is the proportion of the filtered traffic in the total traffic; the system resource consumption parameter and the filtering performance parameter can be unified to the same order of magnitude, and then weighted processing is performed in combination with the weights to obtain the weighted filtering parameters. In a specific embodiment, for example, the maximum value of the system resource consumption parameters corresponding to the multiple data filtering policies is determined, and this maximum value is corresponding to 1, and the system resource consumption parameters corresponding to other data filtering policies are quantified.

[0068] In the above embodiments, by combining the filtering parameters and / or system resource consumption parameters corresponding to the data filtering policies to sort the data filtering policies to obtain the corresponding filtering sorting information, the influence of the different sorting of the multiple data filtering policies on the network intrusion detection efficiency and system performance can be effectively considered, thereby effectively reducing the system resource consumption and greatly improving the network intrusion detection efficiency.

[0069] In the embodiments of this specification, in order to better reduce system resource consumption and improve network intrusion detection efficiency, after performing a full permutation of multiple data filtering policies, that is, after obtaining all permutations and combinations of multiple data filtering policies, use all permutations and combinations to perform data filtering on the preset traffic in sequence, and combine the system resource consumption parameters and / or filtering performance parameters corresponding to each permutation and combination to determine the filtering sorting information of multiple data filtering policies. Optionally, when combining the system resource consumption parameters corresponding to each permutation and combination to determine the filtering sorting information of multiple data filtering policies, the sorting corresponding to the permutation and combination with the smallest system resource consumption parameter can be used as the above inspection sorting information. Optionally, when combining the filtering performance parameters corresponding to each permutation and combination to determine the filtering sorting information of multiple data filtering policies, the sorting corresponding to the permutation and combination with the largest filtering performance parameter can be used as the above inspection sorting information. Optionally, when combining the system resource consumption parameters and / or filtering performance parameters corresponding to each permutation and combination to determine the filtering sorting information of multiple data filtering policies, the weighted filtering parameters corresponding to each permutation and combination (the calculation method of the weighted filtering parameters can refer to the above related steps) can be used to determine the filtering sorting information of multiple data filtering policies. Specifically, when the third weight is a positive number and the fourth weight is a negative number, the sorting corresponding to the permutation and combination with the largest weighted filtering parameter can be used as the above inspection sorting information. On the contrary, when the third weight is a negative number and the fourth weight is a positive or negative number, the sorting corresponding to the permutation and combination with the smallest weighted filtering parameter can be used as the above inspection sorting information.

[0070] In practical applications, since there are a large number of data filtering policies, the number of their sorting combinations will be very large, and it will take a long time to try them all. Correspondingly, in the embodiments of this specification, the divide-and-conquer method can be combined to determine the filtering sorting information of multiple data filtering policies.

[0071] In another optional embodiment, as Figure 5 shown, the pre-determined filtering sorting information may include:

[0072] S501: Obtain the preset traffic and the first preset splitting threshold.

[0073] In the embodiments of this specification, the first preset splitting threshold represents the upper limit of the number of permutations and combinations of data filtering policies in a unit filtering policy group.

[0074] S503: Split the multiple data filtering policies based on the first preset splitting threshold to obtain multiple unit filtering policy groups;

[0075] In the embodiments of this specification, "a plurality" may be at least two; specifically, based on the first preset splitting threshold, the multiple data filtering policies are split to obtain multiple unit filtering policy groups, which include a certain number of network intrusion detection rules. Optionally, the number of data filtering policies in each unit filtering policy group may be the same or different, but the number of data filtering policies in each unit filtering policy group is less than or equal to the first preset splitting threshold.

[0076] S505: Perform a full permutation and combination on the data filtering policies in each unit filtering policy group to obtain multiple permutation filtering policy sets corresponding to each unit filtering policy group.

[0077] In the embodiments of this specification, performing a full permutation and combination on the data filtering policies in each unit filtering policy group to obtain multiple permutation filtering policy sets corresponding to each unit filtering policy group may be all the permutations and combinations of the data filtering policies in each unit filtering policy group. Each permutation filtering policy set may include multiple data filtering policies arranged in order.

[0078] S507: Based on the multiple permutation filtering policy sets, perform data filtering on the preset traffic respectively, and determine the system resource consumption parameters and filtering parameters corresponding to each permutation filtering policy set.

[0079] In the embodiments of this specification, for the specific detailed steps of performing data filtering on the preset traffic respectively based on the multiple permutation filtering policy sets and determining the system resource consumption parameters and filtering parameters corresponding to each permutation filtering policy set, reference may be made to the specific details of determining the system resource consumption parameters and filtering parameters corresponding to each data filtering policy above, which will not be elaborated here.

[0080] S509: According to the filtering parameters and / or system resource consumption parameters of the multiple permutation filtering policy sets corresponding to each unit filtering policy group, determine the target permutation filtering policy set corresponding to each unit filtering policy group;

[0081] In an optional embodiment, when determining the filtering sorting information of multiple data filtering policies by combining the system resource consumption parameters corresponding to multiple permutation filtering policy sets corresponding to each unit filtering policy group, the permutation filtering policy set with the minimum system resource consumption parameter can be used as the target permutation filtering policy set. Optionally, when determining the filtering sorting information of multiple data filtering policies by combining the filtering parameters corresponding to multiple permutation filtering policy sets corresponding to each unit filtering policy group, the permutation filtering policy set with the minimum filtering parameter can be used as the target permutation filtering policy set. Optionally, when determining the filtering sorting information of multiple data filtering policies by combining the filtering parameters and system resource consumption parameters corresponding to multiple permutation filtering policy sets corresponding to each unit filtering policy group, the filtering sorting information of multiple data filtering policies can be determined by combining the weighted filtering parameters (the calculation method of the weighted filtering parameters can refer to the above relevant steps) of each permutation filtering policy set. Specifically, when the third weight is a positive number and the fourth weight is a negative number, the permutation filtering policy set with the largest weighted filtering parameter can be used as the target permutation filtering policy set. On the contrary, when the third weight is a negative number and the fourth weight is a positive or negative number, the permutation filtering policy set with the smallest weighted filtering parameter can be used as the target permutation filtering policy set.

[0082] S511: Based on the merge sub-algorithm in the divide-and-conquer method, merge the target permutation filtering policy sets corresponding to the multiple unit filtering policy groups to obtain the filtering sorting information of the multiple data filtering policies.

[0083] In the embodiments of this specification, merging the target permutation filtering policy sets corresponding to the multiple unit filtering policy groups based on the merge sub-algorithm in the divide-and-conquer method to obtain the filtering sorting information of the multiple data filtering policies may include pairwise merging of multiple target permutation filtering policy sets. When merging, combine the above system resource consumption parameters, or filtering parameters, or the numerical values of the weighted filtering parameters to perform combined sorting on the two target permutation filtering policy sets, and then perform pairwise merging on the permutation filtering policy sets obtained after the combined sorting, and combine the above system resource consumption parameters, or filtering parameters, or the numerical values of the weighted filtering parameters to perform combined sorting on the two target permutation filtering policy sets, until the number of permutation filtering policy sets obtained after the current combined sorting is 1. Use the sorting corresponding to the permutation filtering policy set obtained after the current combined sorting as the filtering sorting information of the multiple data filtering policies.

[0084] In the embodiments of this specification, by combining the divide-and-conquer method to determine the filtering sorting information of multiple data filtering policies, the efficiency of determining the filtering sorting information can be greatly improved. Even when there are a large number of data filtering policies, the filtering sorting information of multiple data filtering policies can be quickly obtained. Moreover, in the above embodiments, by performing a full permutation of multiple data filtering policies and combining the filtering parameters and / or system resource consumption parameters corresponding to the permutation filtering policy set after the full permutation to determine the filtering sorting information, the different sorts of multiple data filtering policies can be fully considered, and the impact on data filtering efficiency and system performance can be taken into account, greatly improving the data filtering efficiency. And by pre-filtering the traffic to be detected, the amount of data processed during subsequent network intrusion detection can be effectively reduced, thereby better reducing system resource consumption and improving the intrusion detection network efficiency.

[0085] S205: Determine multiple network intrusion detection rules corresponding to the traffic to be detected and the detection sorting information of the multiple network intrusion detection rules.

[0086] In practical applications, there are various types of network attacks, and it is often necessary to combine multiple network intrusion detection rules for network intrusion detection. Correspondingly, in the embodiments of this specification, multiple network intrusion detection rules corresponding to the traffic to be detected may include network intrusion detection rules pre-set in the network intrusion detection system. Specifically, the multiple in the embodiments of this specification may be at least two.

[0087] In an optional embodiment, when it is necessary to perform network intrusion detection for a specific application, after the traffic on the replication core switch, the above-mentioned obtaining of the traffic to be detected may further include:

[0088] Determine the identification information of the target detection application;

[0089] Filter the replicated traffic based on the identification information to obtain the traffic to be detected.

[0090] In the embodiments of this specification, the traffic to be detected may often include the identification information of the target detection application, such as IP address information. Correspondingly, by filtering the replicated traffic in combination with the identification information of the target detection application such as IP address information, the traffic including the identification information of the target detection application is selected as the traffic to be detected. In a specific embodiment, as Figure 6 shown Figure 6 is a schematic diagram provided by an embodiment of the present application for mapping a detection application to a network intrusion detection rule. From Figure 6As can be seen, a mapping relationship can be maintained between the application identifier of a detection application (such as application A in the figure) and the identifier information of the application included in the traffic (such as IP1), as well as a mapping relationship between the identifier information of the application included in the traffic and the network intrusion detection rules. Correspondingly, the determination of multiple network intrusion detection rules corresponding to the traffic to be detected may include:

[0091] Determining a target network intrusion detection rule corresponding to the target detection application based on preset mapping information, where the preset mapping information represents a preset relationship between multiple detection applications and corresponding network intrusion detection rules;

[0092] Using the target network intrusion detection rule as the multiple network intrusion detection rules.

[0093] In the embodiments of this specification, the detection sorting information is determined based on the system resource consumption and / or detection performance corresponding to the network intrusion detection of the preset traffic by the multiple network intrusion detection rules respectively.

[0094] In a specific embodiment, the above method may further include the step of pre-determining detection sorting information. Optionally, as Figure 7 shown, pre-determining the detection sorting information may include:

[0095] S701: Obtain preset traffic;

[0096] S703: Perform network intrusion detection on the preset traffic based on the multiple network intrusion detection rules respectively, and obtain the intrusion detection results corresponding to each network intrusion detection rule;

[0097] S705: Use the system resource consumption parameters generated during the network intrusion detection of the preset traffic by each network intrusion detection rule as the system resource consumption parameters corresponding to each network intrusion detection rule;

[0098] S707: Determine the detection parameters corresponding to each data network intrusion detection rule based on the intrusion detection results corresponding to the multiple network intrusion detection rules;

[0099] S709: Determine the detection sorting information of the multiple network intrusion detection rules according to the detection parameters and / or system resource consumption parameters corresponding to the multiple network intrusion detection rules.

[0100] In the embodiments of this specification, the preset traffic may be traffic data within a historical time period. Optionally, the preset traffic may include traffic belonging to network intrusion and may also include traffic not belonging to network intrusion.

[0101] In practical applications, there are various types of network intrusions. In a specific embodiment, the types of network intrusions may include, but are not limited to: Trojans (this type of attack mainly implants Trojans into the server, starts the background, obtains control of the server, maliciously damages server files or steals server data), malicious applets (this type of attack mainly exists in the programs we use. They can modify files on the hard disk and steal passwords by intrusion), SQL injection (the attack means of SQL injection mainly takes advantage of the vulnerabilities in the background, brings key SQL statements into the program through the URL, and causes damage in the database), crawler attacks (illegally obtaining source site page data through automated tools or obtaining illegal business benefits by exploiting business logic defects). Correspondingly, the above-mentioned various network intrusion detection rules can be rules that can detect various network intrusions.

[0102] In a specific embodiment, the inspection result corresponding to each network intrusion detection rule may be traffic belonging to a network intrusion.

[0103] In practical applications, when different network intrusion detection rules perform network intrusion detection, the system resource consumption and detection performance are often different. Specifically, the system resource consumption can be reflected by system resource consumption parameters such as the CPU consumption (unit: Hertz) and the proportion of the consumed CPU. The detection performance can be reflected by detection performance parameters such as the proportion of the traffic belonging to the network intrusion detected in the total traffic. In practical applications, the traffic to be detected can be obtained at a certain frequency, or the operation of obtaining the traffic to be detected can be triggered in combination with the actual application requirements. Correspondingly, the above-mentioned traffic to be detected may include multiple network requests. Optionally, the total traffic may be the number of network requests in the traffic to be detected. Correspondingly, the traffic belonging to the network intrusion detected by a certain network intrusion detection rule may be the number of network requests in the traffic belonging to the network intrusion detected.

[0104] In an alternative embodiment, when determining the detection sorting information of the multiple network intrusion detection rules according to the detection parameters corresponding to the multiple network intrusion detection rules, the multiple network intrusion detection rules can be sorted from largest to smallest according to the numerical values of the detection parameters corresponding to the multiple network intrusion detection rules to obtain the detection sorting information.

[0105] In the above embodiments, in combination with the numerical values of the detection parameters corresponding to the network intrusion detection rules, sorting the multiple network intrusion detection rules from largest to smallest according to the numerical values to obtain the detection sorting information can preferentially perform network intrusion detection by the network intrusion detection rules that can detect more traffic belonging to network intrusion. Correspondingly, the network intrusion detection rules ranked later can perform network intrusion detection on less traffic, thereby reducing system resource consumption and greatly improving the network intrusion detection efficiency.

[0106] In a specific embodiment, when determining the detection sorting information of the multiple network intrusion detection rules according to the system resource consumption parameters corresponding to the multiple network intrusion detection rules, the multiple network intrusion detection rules can be sorted from smallest to largest according to the numerical values of the system resource consumption parameters corresponding to the multiple network intrusion detection rules to obtain the detection sorting information.

[0107] In the above embodiments, in combination with the numerical values of the system resource consumption parameters corresponding to the network intrusion detection rules, sorting the multiple network intrusion detection rules from smallest to largest according to the numerical values to obtain the detection sorting information can consume less system performance in the early stage, and at the same time can detect a part of the traffic belonging to network intrusion first, so that the network intrusion detection rules with larger subsequent system resource consumption can perform network intrusion detection on less traffic, thereby reducing system resource consumption and improving the network intrusion detection efficiency.

[0108] When determining the detection sorting information of the multiple network intrusion detection rules according to the detection parameters and system resource consumption parameters corresponding to the multiple network intrusion detection rules, the first weight corresponding to the detection parameters and the second weight corresponding to the system resource consumption parameters can be determined, and the detection parameters and system resource consumption parameters corresponding to each network intrusion detection rule are weighted based on the first weight and the second weight to obtain the weighted detection parameters; the multiple network intrusion detection rules are sorted according to the numerical values of the weighted detection parameters to obtain the detection sorting information.

[0109] In the embodiments of this specification, the signs of the first weight and the second weight may be opposite, the sum of the absolute values of the first weight and the second weight may be 1, and the specific values of the first weight and the second weight may be preset in combination with actual applications. In a specific embodiment, for example, the absolute value of the first weight is 0.95 and the absolute value of the second weight is 0.05. Optionally, when the first weight is positive and the second weight is negative, sorting multiple network intrusion detection rules according to the value of the weighted detection parameter to obtain detection sorting information may include sorting multiple network intrusion detection rules from large to small according to the value of the weighted detection parameter to obtain detection sorting information. Conversely, when the first weight is negative and the second weight is positive, sorting multiple network intrusion detection rules according to the value of the weighted detection parameter to obtain detection sorting information may include sorting multiple network intrusion detection rules from small to large according to the value of the weighted detection parameter to obtain detection sorting information.

[0110] Optionally, when the detection parameter and the system resource consumption parameter do not belong to data of the same order of magnitude. For example, the system resource consumption parameter is the cup consumption; the detection performance parameter is the proportion of the traffic detected as network intrusion in the total traffic. The system resource consumption parameter and the detection performance parameter can be unified to the same order of magnitude, and then weighted processing is performed in combination with the weights to obtain the weighted detection parameter. In a specific embodiment, for example, determine the maximum value of the system resource consumption parameters corresponding to multiple network intrusion detection rules, correspond this maximum value to 1, and quantify the system resource consumption parameters corresponding to other network intrusion detection rules.

[0111] In the above embodiments, sorting the network intrusion detection rules by combining the detection parameters and / or system resource consumption parameters corresponding to the network intrusion detection rules to obtain the corresponding detection sorting information can effectively consider the influence of the different sorting of multiple network intrusion detection rules on the network intrusion detection efficiency and system performance, and then effectively reduce the system resource consumption and greatly improve the network intrusion detection efficiency.

[0112] In the embodiments of this specification, in order to better reduce system resource consumption and improve the efficiency of network intrusion detection, after performing a full permutation on multiple network intrusion detection rules, that is, after obtaining all permutations and combinations of multiple network intrusion detection rules, use all permutations and combinations to perform network intrusion detection on the preset traffic in sequence, and combine the system resource consumption parameters and / or detection performance parameters corresponding to each permutation and combination to determine the detection sorting information of multiple network intrusion detection rules. Optionally, when combining the system resource consumption parameters corresponding to each permutation and combination to determine the detection sorting information of multiple network intrusion detection rules, the sorting corresponding to the permutation and combination with the smallest system resource consumption parameter can be used as the above inspection sorting information. Optionally, by combining the detection performance parameters corresponding to each permutation and combination to determine the detection sorting information of multiple network intrusion detection rules, the sorting corresponding to the permutation and combination with the largest detection performance parameter can be used as the above inspection sorting information. Optionally, when combining the system resource consumption parameters and / or detection performance parameters corresponding to each permutation and combination to determine the detection sorting information of multiple network intrusion detection rules, the weighted detection parameters corresponding to each permutation and combination (the calculation method of the weighted detection parameters can refer to the above related steps) can be used to determine the detection sorting information of multiple network intrusion detection rules. Specifically, when the first weight is a positive number and the second weight is a negative number, the sorting corresponding to the permutation and combination with the largest weighted detection parameter can be used as the above inspection sorting information. Conversely, when the first weight is a negative number and the second weight is a positive or negative number, the sorting corresponding to the permutation and combination with the smallest weighted detection parameter can be used as the above inspection sorting information.

[0113] In practical applications, due to the large number of types of network intrusions, there are also a large number of corresponding network intrusion detection rules. Sorting and combining them will result in a large number, and trying them all will take a long time. Accordingly, in the embodiments of this specification, the divide-and-conquer method can be combined to determine the detection sorting information of multiple network intrusion detection rules.

[0114] In another optional embodiment, as Figure 8 shown, the pre-determined detection sorting information may include:

[0115] S801: Obtain the preset traffic and the second preset splitting threshold.

[0116] In the embodiments of this specification, the second preset splitting threshold may represent the upper limit of the permutation and combination quantity of network intrusion detection rules in a unit detection rule group.

[0117] S803: Based on the second preset splitting threshold, split the multiple network intrusion detection rules to obtain multiple unit detection rule groups;

[0118] In the embodiments of this specification, "a plurality" may be at least two; specifically, based on the second preset splitting threshold, the multiple network intrusion detection rules are split to obtain multiple unit detection rule groups, which may include a certain number of network intrusion detection rules. Optionally, the number of network intrusion detection rules in each unit detection rule group may be the same or different, but the number of network intrusion detection rules in each unit detection rule group is less than or equal to the second preset splitting threshold.

[0119] S805: Perform a full permutation and combination on the network intrusion detection rules in each unit detection rule group to obtain multiple permutation detection rule sets corresponding to each unit detection rule group;

[0120] In the embodiments of this specification, performing a full permutation and combination on the network intrusion detection rules in each unit detection rule group to obtain multiple permutation detection rule sets corresponding to each unit detection rule group may be all the permutation and combinations of the network intrusion detection rules in each unit detection rule group. Each permutation filtering strategy set may include multiple network intrusion detection rules arranged in order.

[0121] S807: Based on the multiple permutation detection rule sets, perform network intrusion detection on the preset traffic respectively, and determine the system resource consumption parameters and detection parameters corresponding to each permutation detection rule set;

[0122] In the embodiments of this specification, for the specific detailed steps of performing network intrusion detection on the preset traffic respectively based on the multiple permutation detection rule sets and determining the system resource consumption parameters and detection parameters corresponding to each permutation detection rule set, reference may be made to the specific details of determining the system resource consumption parameters and detection parameters corresponding to each network intrusion detection rule above, which will not be elaborated here.

[0123] S809: According to the detection parameters and / or system resource consumption parameters corresponding to the multiple permutation detection rule sets corresponding to each unit detection rule group, determine the target permutation detection rule set corresponding to each unit detection rule group.

[0124] In an optional embodiment, when determining the detection sorting information of multiple network intrusion detection rules by combining the system resource consumption parameters corresponding to multiple permutation detection rule sets corresponding to each unit detection rule group, the permutation detection rule set with the minimum system resource consumption parameter can be used as the target permutation detection rule set. Optionally, when determining the detection sorting information of multiple network intrusion detection rules by combining the detection parameters corresponding to multiple permutation detection rule sets corresponding to each unit detection rule group, the permutation detection rule set with the minimum detection parameter can be used as the target permutation detection rule set. Optionally, when determining the detection sorting information of multiple network intrusion detection rules by combining the detection parameters and system resource consumption parameters corresponding to multiple permutation detection rule sets corresponding to each unit detection rule group, the detection sorting information of multiple network intrusion detection rules can be determined by combining the weighted detection parameters (the calculation method of the weighted detection parameters can refer to the above relevant steps) of each permutation detection rule set. Specifically, when the first weight is a positive number and the second weight is a negative number, the permutation detection rule set with the maximum weighted detection parameter can be used as the target permutation detection rule set. Conversely, when the first weight is a negative number and the second weight is a positive or negative number, the permutation detection rule set with the minimum weighted detection parameter can be used as the target permutation detection rule set.

[0125] S811: Based on the merging sub-algorithm in the divide-and-conquer method, merge the target permutation detection rule sets corresponding to the multiple unit detection rule groups to obtain the detection sorting information of the multiple network intrusion detection rules.

[0126] In the embodiments of this specification, merging the target permutation detection rule sets corresponding to the multiple unit detection rule groups based on the merging sub-algorithm in the divide-and-conquer method to obtain the detection sorting information of the multiple network intrusion detection rules may include pairwise merging of multiple target permutation detection rule sets. When merging, combine the above system resource consumption parameters, or detection parameters, or the numerical magnitudes of the weighted detection parameters to perform combined sorting on the two target permutation detection rule sets, and then perform pairwise merging on the permutation detection rule sets obtained after the combined sorting, and combine the above system resource consumption parameters, or detection parameters, or the numerical magnitudes of the weighted detection parameters to perform combined sorting on the two target permutation detection rule sets until the number of permutation detection rule sets obtained after the current combined sorting is 1. Take the sorting corresponding to the permutation detection rule set obtained after the current combined sorting as the detection sorting information of the multiple network intrusion detection rules.

[0127] In the embodiments of this specification, by combining the divide-and-conquer method to determine the detection sorting information of multiple network intrusion detection rules, the efficiency of determining the detection sorting information can be greatly improved. Even when there are a large number of network intrusion detection rules, the detection sorting information of multiple network intrusion detection rules can be quickly obtained. Moreover, in the above embodiments, by performing a full permutation of various network intrusion detection rules and combining the detection parameters and / or system resource consumption parameters corresponding to the permutation detection rule sets after the full permutation to determine the detection sorting information, the impact of different sorting of various network intrusion detection rules on the network intrusion detection efficiency and system performance can be fully considered, thereby better reducing the system resource consumption and greatly improving the network intrusion detection efficiency.

[0128] S207: Based on the multiple network intrusion detection rules and the detection sorting information, perform network intrusion detection on the filtered traffic data to obtain a target intrusion detection result.

[0129] In an optional embodiment, performing network intrusion detection on the filtered traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result may include:

[0130] Traverse the multiple network intrusion detection rules according to the detection sorting information;

[0131] When traversing to any network intrusion detection rule, use the currently traversed network intrusion detection rule to perform network intrusion detection on the traffic to be detected, and obtain the network intrusion detection result corresponding to the currently traversed network intrusion detection rule;

[0132] Take the network intrusion detection rules obtained during the traversal process as the target intrusion detection result.

[0133] In another optional embodiment, when the currently traversed network intrusion detection rule includes a target rule for performing network intrusion detection on target data within a preset time period, the step of using the currently traversed network intrusion detection rule to perform network intrusion detection on the traffic to be detected and obtaining the network intrusion detection result corresponding to the currently traversed network intrusion detection rule may include:

[0134] Obtain the target data within the preset time period from the traffic to be detected;

[0135] Based on the target rule, perform network intrusion detection on the target data to obtain the network intrusion detection result corresponding to the target rule.

[0136] In the embodiments of this specification, the above preset time period is included in the time period for collecting the traffic to be detected.

[0137] In practical applications, the URLs in network requests can only be sent over the Internet using the ASCII character set. Since URLs often contain characters outside the ASCII set, the URLs in the network requests (traffic to be detected) sent to the interaction must be converted to a valid ASCII format. Correspondingly, before performing network intrusion detection on the filtered traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain the target intrusion detection result, as Figure 9 shown, the above method may further include:

[0138] S211: Perform decoding processing on the filtered traffic data to obtain decoded traffic data;

[0139] Correspondingly, the performing network intrusion detection on the filtered traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain the target intrusion detection result includes: performing network intrusion detection on the decoded traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain the target intrusion detection result.

[0140] In addition, it should be noted that generally, data filtering can be directly performed on the traffic to be detected without prior decoding processing.

[0141] In a specific embodiment, assume that it is necessary to detect a crawler attack on a certain application. Correspondingly, since crawler attack detection needs to be identified by combining whether the number of requests within a period of time exceeds a preset request volume threshold, correspondingly, the identification information such as the IP address information corresponding to a certain application can be obtained from the traffic to be detected for the data corresponding to the identification information within a period of time as the above target data, and combined with the crawler attack detection rules (i.e., target rules) to perform crawler attack detection.

[0142] In an alternative embodiment, after performing network intrusion detection on the filtered traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain the target intrusion detection result, as Figure 10 shown, the above method may further include:

[0143] S213: Send an alarm notification based on the target intrusion detection result.

[0144] In practical applications, when the target network intrusion detection result indicates that the current network is at risk, an alarm notification can be sent to facilitate timely system repair.

[0145] As can be seen from the technical solutions provided in the embodiments of this specification above, when performing network intrusion detection on the traffic to be detected in the embodiments of this specification, first, in combination with the filtering sorting information determined based on the system resource consumption and / or filtering performance corresponding to filtering the preset traffic respectively by multiple data filtering strategies, it is possible to fully consider the different sorting of multiple data filtering strategies and their impacts on data filtering efficiency and system performance, greatly improving the data filtering efficiency. And by pre-filtering the traffic to be detected, the amount of data processed during subsequent network intrusion detection can be effectively reduced. Then, in combination with the detection sorting information determined based on the system resource consumption and / or detection performance corresponding to performing network intrusion detection on the preset traffic respectively by multiple network intrusion detection rules, it is possible to effectively consider the different sorting of multiple network intrusion detection rules and their impacts on network intrusion detection efficiency and system performance, thereby effectively reducing the system resource consumption and greatly improving the network intrusion detection efficiency. Moreover, no hardware upgrades or improvements are required during the implementation process in the above embodiments, which can effectively reduce costs. And through multiple network intrusion detection rules, the inspection requirements under different applications and different network architectures can be effectively met, enhancing the generality of network intrusion detection.

[0146] The embodiments of this application also provide a network intrusion detection device, as Figure 11 shown. The device includes:

[0147] A traffic-to-be-detected acquisition module 1110, configured to acquire the traffic to be detected;

[0148] A first data filtering module 1120, configured to perform data filtering on the traffic to be detected based on multiple data filtering strategies and the filtering sorting information of the multiple data filtering strategies to obtain filtered traffic data; the filtering sorting information is determined based on the system resource consumption and / or filtering performance corresponding to filtering the preset traffic respectively by the multiple data filtering strategies;

[0149] A data determination module 1130, configured to determine multiple network intrusion detection rules corresponding to the traffic to be detected and the detection sorting information of the multiple network intrusion detection rules, where the detection sorting information is determined based on the system resource consumption and / or detection performance corresponding to performing network intrusion detection on the preset traffic respectively by the multiple network intrusion detection rules;

[0150] A first network intrusion detection module 1140, configured to perform network intrusion detection on the filtered traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result.

[0151] Optionally, the device further includes:

[0152] The first data acquisition module is used to acquire the multiple data filtering policies and the filtering sorting information of the multiple data filtering policies.

[0153] Optionally, the above method further includes:

[0154] The second data acquisition module is used to acquire a preset traffic volume and a first preset splitting threshold, where the first preset splitting threshold represents the upper limit of the permutation and combination quantity of data filtering policies in a unit filtering policy group;

[0155] The policy splitting module is used to split the multiple data filtering policies based on the first preset splitting threshold to obtain multiple unit filtering policy groups;

[0156] The first full permutation and combination module is used to perform full permutation and combination on the data filtering policies in each unit filtering policy group to obtain multiple permutation filtering policy sets corresponding to each unit filtering policy group, and each permutation filtering policy set includes multiple data filtering policies arranged in order;

[0157] The second data filtering module is used to perform data filtering on the preset traffic volume based on the multiple permutation filtering policy sets respectively to determine the system resource consumption parameters and filtering parameters corresponding to each permutation filtering policy set;

[0158] The target permutation filtering policy set determination module is used to determine the target permutation filtering policy set corresponding to each unit filtering policy group according to the filtering parameters and / or system resource consumption parameters of the multiple permutation filtering policy sets corresponding to each unit filtering policy group;

[0159] The first merging module is used to merge the target permutation filtering policy sets corresponding to the multiple unit filtering policy groups based on the merge sub-algorithm in the divide-and-conquer method to obtain the filtering sorting information of the multiple data filtering policies.

[0160] Optionally, the device further includes:

[0161] The first preset traffic volume acquisition module is used to acquire a preset traffic volume;

[0162] The second data filtering module is used to perform data filtering on the preset traffic volume based on the multiple data filtering policies respectively to obtain the filtering results corresponding to each data filtering policy;

[0163] The first system resource consumption parameter determination module is used to use the system resource consumption parameters generated during the filtering of the preset traffic volume by each data filtering policy as the system resource consumption parameters corresponding to each data filtering policy;

[0164] The filtering parameter determination module is used to determine the filtering parameters corresponding to each data filtering policy based on the filtering results corresponding to the multiple data filtering policies;

[0165] A filtering and sorting information determination module, configured to determine the filtering and sorting information of the multiple data filtering policies according to the filtering parameters corresponding to the multiple data filtering policies and / or the system resource consumption parameters.

[0166] Optionally, the device further includes:

[0167] A third data acquisition module, configured to acquire a preset traffic volume and a second preset splitting threshold, where the second preset splitting threshold represents the upper limit of the permutation and combination quantity of network intrusion detection rules in a unit detection rule group;

[0168] A rule splitting module, configured to split the multiple network intrusion detection rules based on the second preset splitting threshold to obtain multiple unit detection rule groups;

[0169] A second full permutation and combination module, configured to perform a full permutation and combination on the network intrusion detection rules in each unit detection rule group to obtain multiple permutation detection rule sets corresponding to each unit detection rule group, where each permutation detection rule set includes multiple network intrusion detection rules arranged in sequence;

[0170] A second network intrusion detection module, configured to perform network intrusion detection on the preset traffic volume based on the multiple permutation detection rule sets respectively, and determine the system resource consumption parameters and detection parameters corresponding to each permutation detection rule set;

[0171] A target permutation detection rule set determination module, configured to determine the target permutation detection rule set corresponding to each unit detection rule group according to the detection parameters and / or system resource consumption parameters corresponding to the multiple permutation detection rule sets corresponding to each unit detection rule group;

[0172] A second merging module, configured to merge the target permutation detection rule sets corresponding to the multiple unit detection rule groups based on the merge sub-algorithm in the divide-and-conquer method to obtain the detection and sorting information of the multiple network intrusion detection rules.

[0173] Optionally, the device further includes:

[0174] A second preset traffic volume module, configured to acquire a preset traffic volume;

[0175] A third network intrusion detection module, configured to perform network intrusion detection on the preset traffic volume based on the multiple network intrusion detection rules respectively, and obtain the intrusion detection results corresponding to each network intrusion detection rule;

[0176] A second system resource consumption parameter determination module, configured to use the system resource consumption parameters generated during the process of performing network intrusion detection on the preset traffic volume by each network intrusion detection rule as the system resource consumption parameters corresponding to each network intrusion detection rule;

[0177] A detection parameter determination module, configured to determine detection parameters corresponding to each data network intrusion detection rule based on intrusion detection results corresponding to the multiple network intrusion detection rules;

[0178] A detection sorting information determination module, configured to determine detection sorting information for the multiple network intrusion detection rules according to the detection parameters corresponding to the multiple network intrusion detection rules and / or system resource consumption parameters.

[0179] Optionally, the traffic to be detected acquisition module 1110 includes:

[0180] A traffic replication unit, configured to replicate traffic on a core switch;

[0181] A traffic to be detected determination unit, configured to use the replicated traffic as the traffic to be detected.

[0182] Optionally, the traffic to be detected acquisition module 1110 further includes:

[0183] An identification information determination unit, configured to determine identification information of a target detection application;

[0184] A traffic filtering unit, configured to filter the replicated traffic based on the identification information to obtain the traffic to be detected.

[0185] Optionally, the data determination module 1130 includes:

[0186] A target network intrusion detection rule determination unit, configured to determine a target network intrusion detection rule corresponding to the target detection application based on preset mapping information, where the preset mapping information represents a preset relationship between multiple detection applications and corresponding network intrusion detection rules;

[0187] A network intrusion detection rule determination unit, configured to use the corresponding target network intrusion detection rule as the multiple network intrusion detection rules.

[0188] Optionally, the device further includes:

[0189] A decoding processing module, configured to perform decoding processing on the filtered traffic data to obtain decoded traffic data before performing network intrusion detection on the filtered traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result;

[0190] The first network intrusion detection module 1140 is further configured to perform network intrusion detection on the decoded traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result.

[0191] Optionally, the first network intrusion detection module 1140 includes:

[0192] A network intrusion detection rule traversal unit, configured to traverse the multiple network intrusion detection rules according to the detection sorting information;

[0193] A network intrusion detection unit, configured to, when any network intrusion detection rule is traversed, use the currently traversed network intrusion detection rule to perform network intrusion detection on the traffic to be detected, and obtain a network intrusion detection result corresponding to the currently traversed network intrusion detection rule;

[0194] A target intrusion detection result determination unit, configured to use the network intrusion detection rules obtained during the traversal process as the target intrusion detection result.

[0195] Optionally, when the currently traversed network intrusion detection rule includes a target rule for performing network intrusion detection on target data within a preset time period, the network intrusion detection unit includes:

[0196] A target data acquisition unit, configured to acquire target data within a preset time period from the traffic to be detected;

[0197] A network intrusion detection subunit, configured to perform network intrusion detection on the target data based on the target rule, and obtain a network intrusion detection result corresponding to the target rule.

[0198] The device in the device embodiment and the method embodiment are based on the same application concept.

[0199] An embodiment of the present application provides a network intrusion detection device, which includes a processor and a memory. At least one instruction or at least one program segment is stored in the memory, and the at least one instruction or the at least one program segment is loaded and executed by the processor to implement the network intrusion detection method provided in the above method embodiment.

[0200] The memory can be used to store software programs and modules. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for functions, etc.; the data storage area can store data created according to the use of the device. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices. Correspondingly, the memory can also include a memory controller to provide the processor with access to the memory.

[0201] The method embodiments provided in the embodiments of the present application can be executed on a mobile terminal, a computer terminal, a server, or a similar computing device. Taking running on a server as an example, Figure 12 is a hardware block diagram of a server for implementing a network intrusion detection method provided in an embodiment of the present application. As Figure 12 shown, the server 1200 may vary greatly due to configuration or performance differences, and may include one or more central processing units (CPUs) 1210 (the processor 1210 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 1230 for storing data, and one or more storage media 1220 for storing application programs 1223 or data 1222 (such as one or more mass storage devices). Among them, the memory 1230 and the storage media 1220 may be transient storage or persistent storage. The program stored in the storage media 1220 may include one or more modules, and each module may include a series of instruction operations on the server. Further, the central processor 1210 may be configured to communicate with the storage media 1220 and execute a series of instruction operations in the storage media 1220 on the server 1200. The server 1200 may also include one or more power supplies 1260, one or more wired or wireless network interfaces 1250, one or more input / output interfaces 1240, and / or one or more operating systems 1221, such as Windows Server TM , MacOS X TM , Unix TM , Linux TM , FreeBSD TM and so on.

[0202] The input / output interface 1240 can be used to receive or send data via a network. The specific instance of the above network may include a wireless network provided by the communication provider of the server 1200. In one instance, the input / output interface 1240 includes a network interface controller (NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the input / output interface 1240 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0203] Those of ordinary skill in the art can understand that Figure 12 the structure shown is only schematic and does not limit the structure of the above electronic device. For example, the server 1200 may also include more than Figure 12more or fewer components shown, or having a configuration different from that shown in Figure 12 that shown.

[0204] Embodiments of the present application also provide a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in the above various alternative implementation manners.

[0205] Embodiments of the present application also provide a storage medium. The storage medium can be disposed in a device to store at least one instruction or at least one segment of a program related to a network intrusion detection method in a method embodiment. The at least one instruction or the at least one segment of the program is loaded and executed by the processor to implement the network intrusion detection method provided in the above method embodiment.

[0206] Optionally, in this embodiment, the above storage medium may be located in at least one of multiple network servers in a computer network. Optionally, in this embodiment, the above storage medium may include, but is not limited to, various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc.

[0207] It can be seen from the embodiments of the network intrusion detection method, device, equipment, server, or storage medium provided by the present application that when performing network intrusion detection on the traffic to be detected, the present application first combines the filtering sorting information determined based on the system resource consumption and / or filtering performance corresponding to filtering the preset traffic by using a variety of data filtering strategies, which can fully consider the influence of the different sorting of a variety of data filtering strategies on the data filtering efficiency and system performance, greatly improve the data filtering efficiency, and effectively reduce the amount of data processed during subsequent network intrusion detection by pre-filtering the traffic to be detected; then, combines the detection sorting information determined based on the system resource consumption and / or detection performance corresponding to performing network intrusion detection on the preset traffic by using a variety of network intrusion detection rules, which can effectively consider the influence of the different sorting of a variety of network intrusion detection rules on the network intrusion detection efficiency and system performance, thereby effectively reducing the system resource consumption, greatly improving the network intrusion detection efficiency, and in the implementation process of the above embodiments, no hardware upgrade or improvement is required, which can effectively reduce the cost, and can effectively meet the inspection requirements under different applications and different network architectures through a variety of network intrusion detection rules, improving the versatility of network intrusion detection.

[0208] It should be noted that the above sequence of the embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above description of specific embodiments of this specification is made. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0209] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the embodiments of the device, equipment, server, and storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.

[0210] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium. The above-mentioned storage medium can be a read-only memory, a disk, an optical disc, or the like.

[0211] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A network intrusion detection method, characterized in that, the method includes: obtaining the traffic to be detected corresponding to the target detection application; performing data filtering on the traffic to be detected based on a variety of data filtering policies and the filtering sorting information of the variety of data filtering policies to obtain filtered traffic data; the filtering sorting information is determined based on the system resource consumption and / or filtering performance corresponding to filtering the preset traffic by the variety of data filtering policies respectively; determining a variety of network intrusion detection rules corresponding to the target detection application and the detection sorting information of the variety of network intrusion detection rules; performing network intrusion detection on the filtered traffic data based on the variety of network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result; the detection sorting information is determined by the following method: splitting the variety of network intrusion detection rules based on a second preset splitting threshold to obtain multiple unit detection rule groups, where the second preset splitting threshold represents the upper limit of the permutation and combination quantity of the network intrusion detection rules in the unit detection rule group; performing full permutation and combination on the network intrusion detection rules in each unit detection rule group to obtain multiple permutation detection rule sets corresponding to each unit detection rule group; performing network intrusion detection on the preset traffic based on the multiple permutation detection rule sets respectively to determine the system resource consumption parameters and detection parameters corresponding to each permutation detection rule set; the preset traffic is the traffic data within a historical time period; determining the target permutation detection rule set corresponding to each unit detection rule group according to the detection parameters and / or system resource consumption parameters corresponding to the multiple permutation detection rule sets corresponding to each unit detection rule group; merging the target permutation detection rule sets corresponding to the multiple unit detection rule groups based on the merge sub-algorithm in the divide-and-conquer method to obtain the detection sorting information of the variety of network intrusion detection rules.

2. The method according to claim 1, characterized in that, before performing data filtering on the traffic to be detected based on a variety of data filtering policies and the filtering sorting information of the variety of data filtering policies to obtain filtered traffic data, the method further includes: obtaining the variety of data filtering policies and the filtering sorting information of the variety of data filtering policies.

3. The method according to claim 2, characterized in that, the method further includes: obtaining a preset traffic and a first preset splitting threshold, where the first preset splitting threshold represents the upper limit of the permutation and combination quantity of the data filtering policies in the unit filtering policy group; splitting the variety of data filtering policies based on the first preset splitting threshold to obtain multiple unit filtering policy groups; performing full permutation and combination on the data filtering policies in each unit filtering policy group to obtain multiple permutation filtering policy sets corresponding to each unit filtering policy group, and each permutation filtering policy set includes multiple data filtering policies arranged in sequence; performing data filtering on the preset traffic based on the multiple permutation filtering policy sets respectively to determine the system resource consumption parameters and filtering parameters corresponding to each permutation filtering policy set; Determine the target permutation filtering policy set corresponding to each unit filtering policy group according to the filtering parameters and / or system resource consumption parameters of the multiple permutation filtering policy sets corresponding to each unit filtering policy group; Based on the merging sub-algorithm in the divide-and-conquer method, merge the target permutation filtering policy sets corresponding to the multiple unit filtering policy groups to obtain the filtering sorting information of the multiple data filtering policies.

4. The method according to claim 2, wherein, the method further includes: Obtain a preset traffic volume; Based on the multiple data filtering policies, respectively perform data filtering on the preset traffic volume to obtain a filtering result corresponding to each data filtering policy; Use the system resource consumption parameters generated during the process of filtering the preset traffic volume by each data filtering policy as the system resource consumption parameters corresponding to each data filtering policy; Based on the filtering results corresponding to the multiple data filtering policies, determine the filtering parameters corresponding to each data filtering policy; Determine the filtering sorting information of the multiple data filtering policies according to the filtering parameters and / or system resource consumption parameters corresponding to the multiple data filtering policies.

5. The method according to claim 1, wherein, the method further includes: Obtain a preset traffic volume; Based on the multiple network intrusion detection rules, respectively perform network intrusion detection on the preset traffic volume to obtain an intrusion detection result corresponding to each network intrusion detection rule; Use the system resource consumption parameters generated during the process of performing network intrusion detection on the preset traffic volume by each network intrusion detection rule as the system resource consumption parameters corresponding to each network intrusion detection rule; Based on the intrusion detection results corresponding to the multiple network intrusion detection rules, determine the detection parameters corresponding to each data network intrusion detection rule; Determine the detection sorting information of the multiple network intrusion detection rules according to the detection parameters and / or system resource consumption parameters corresponding to the multiple network intrusion detection rules.

6. The method according to any one of claims 1 to 5, wherein, the obtaining of the traffic to be detected corresponding to the target detection application includes: Copy the traffic on the core switch; Use the copied traffic as the traffic to be detected.

7. The method according to claim 6, wherein, after copying the traffic on the core switch, the obtaining of the traffic to be detected corresponding to the target detection application further includes: Determine the identification information of the target detection application; Based on the identification information, filter the copied traffic to obtain the traffic to be detected.

8. The method according to claim 7, wherein, the determining of the multiple network intrusion detection rules corresponding to the target detection application includes: Based on preset mapping information, determine the target network intrusion detection rule corresponding to the target detection application, where the preset mapping information represents a preset relationship between multiple detection applications and corresponding network intrusion detection rules; Use the corresponding target network intrusion detection rule as the multiple network intrusion detection rules.

9. The method according to any one of claims 1 to 5, wherein, Before performing network intrusion detection on the filtered traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result, the method further includes: Performing decoding processing on the filtered traffic data to obtain decoded traffic data; The performing network intrusion detection on the filtered traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result includes: performing network intrusion detection on the decoded traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result.

10. The method according to any one of claims 1 to 5, wherein, The performing network intrusion detection on the filtered traffic data based on the multiple network intrusion detection rules and the detection sorting information to obtain a target intrusion detection result includes: Traversing the multiple network intrusion detection rules according to the detection sorting information; When any network intrusion detection rule is traversed, using the currently traversed network intrusion detection rule to perform network intrusion detection on the traffic to be detected, and obtaining a network intrusion detection result corresponding to the currently traversed network intrusion detection rule; Taking the network intrusion detection results obtained during the traversal process as the target intrusion detection results.

11. The method according to claim 10, wherein, When the currently traversed network intrusion detection rule includes a target rule for performing network intrusion detection on target data within a preset time period, the using the currently traversed network intrusion detection rule to perform network intrusion detection on the traffic to be detected and obtaining a network intrusion detection result corresponding to the currently traversed network intrusion detection rule includes: Obtaining target data within a preset time period from the traffic to be detected; Performing network intrusion detection on the target data based on the target rule to obtain a network intrusion detection result corresponding to the target rule.

12. A network intrusion detection device, wherein, The device includes: A traffic to be detected acquisition module, configured to acquire traffic to be detected corresponding to a target detection application; A first data filtering module, configured to perform data filtering on the traffic to be detected based on multiple data filtering policies and filtering sorting information of the multiple data filtering policies, and obtain filtered traffic data; the filtering sorting information is determined based on system resource consumption and / or filtering performance corresponding to filtering the preset traffic by the multiple data filtering policies respectively; A data determination module, configured to determine multiple network intrusion detection rules corresponding to the target detection application and detection sorting information of the multiple network intrusion detection rules; A first network intrusion detection module, configured to perform network intrusion detection on the filtered traffic data based on the multiple network intrusion detection rules and the detection sorting information, and obtain a target intrusion detection result; A rule splitting module, configured to split the multiple network intrusion detection rules based on a second preset splitting threshold to obtain multiple unit detection rule groups, where the second preset splitting threshold represents the upper limit of the permutation and combination quantity of the network intrusion detection rules in a unit detection rule group; A second full permutation and combination module, configured to perform full permutation and combination on the network intrusion detection rules in each unit detection rule group to obtain multiple permutation detection rule sets corresponding to each unit detection rule group; A second network intrusion detection module, configured to perform network intrusion detection on preset traffic based on the multiple permutation detection rule sets respectively, and determine system resource consumption parameters and detection parameters corresponding to each permutation detection rule set; the preset traffic is traffic data within a historical time period; A target permutation detection rule set determination module, configured to determine a target permutation detection rule set corresponding to each unit detection rule group according to the detection parameters and / or system resource consumption parameters corresponding to the multiple permutation detection rule sets corresponding to each unit detection rule group; A second merging module, configured to merge the target permutation detection rule sets corresponding to the multiple unit detection rule groups based on the merging sub-algorithm in the divide-and-conquer method to obtain the detection sorting information of the multiple network intrusion detection rules.

13. The apparatus according to claim 12, wherein, the apparatus further comprises: A first data acquisition module, configured to acquire the multiple data filtering policies and the filtering sorting information of the multiple data filtering policies.

14. The apparatus according to claim 13, wherein, the apparatus further comprises: A second data acquisition module, configured to acquire preset traffic and a first preset splitting threshold, where the first preset splitting threshold represents the upper limit of the permutation and combination quantity of the data filtering policies in a unit filtering policy group; A policy splitting module, configured to split the multiple data filtering policies based on the first preset splitting threshold to obtain multiple unit filtering policy groups; A first full permutation and combination module, configured to perform full permutation and combination on the data filtering policies in each unit filtering policy group to obtain multiple permutation filtering policy sets corresponding to each unit filtering policy group, and each permutation filtering policy set includes multiple data filtering policies arranged in sequence; A second data filtering module, configured to perform data filtering on the preset traffic based on the multiple permutation filtering policy sets respectively, and determine system resource consumption parameters and filtering parameters corresponding to each permutation filtering policy set; A target permutation filtering policy set determination module, configured to determine a target permutation filtering policy set corresponding to each unit filtering policy group according to the filtering parameters and / or system resource consumption parameters corresponding to the multiple permutation filtering policy sets corresponding to each unit filtering policy group; A first merging module, configured to merge the target permutation filtering policy sets corresponding to the multiple unit filtering policy groups based on the merging sub-algorithm in the divide-and-conquer method to obtain the filtering sorting information of the multiple data filtering policies.

15. The apparatus according to claim 13, wherein, the apparatus further comprises: A first preset traffic acquisition module, configured to acquire preset traffic; The second data filtering module is configured to perform data filtering on the preset traffic respectively based on the multiple data filtering policies, and obtain a filtering result corresponding to each data filtering policy; The first system resource consumption parameter determination module is configured to use the system resource consumption parameters generated during the filtering of the preset traffic by each data filtering policy as the system resource consumption parameters corresponding to each data filtering policy; The filtering parameter determination module is configured to determine the filtering parameters corresponding to each data filtering policy based on the filtering results corresponding to the multiple data filtering policies; The filtering sorting information determination module is configured to determine the filtering sorting information of the multiple data filtering policies according to the filtering parameters and / or system resource consumption parameters corresponding to the multiple data filtering policies.

16. The apparatus according to claim 12, wherein, the apparatus further comprises: The second preset traffic module is configured to obtain preset traffic; The third network intrusion detection module is configured to perform network intrusion detection on the preset traffic respectively based on the multiple network intrusion detection rules, and obtain an intrusion detection result corresponding to each network intrusion detection rule; The second system resource consumption parameter determination module is configured to use the system resource consumption parameters generated during the network intrusion detection of the preset traffic by each network intrusion detection rule as the system resource consumption parameters corresponding to each network intrusion detection rule; The detection parameter determination module is configured to determine the detection parameters corresponding to each data network intrusion detection rule based on the intrusion detection results corresponding to the multiple network intrusion detection rules; The detection sorting information determination module is configured to determine the detection sorting information of the multiple network intrusion detection rules according to the detection parameters and / or system resource consumption parameters corresponding to the multiple network intrusion detection rules.

17. The apparatus according to any one of claims 12 to 16, wherein, the to-be-detected traffic acquisition module comprises: The traffic replication unit is configured to replicate the traffic on the core switch; The to-be-detected traffic determination unit is configured to use the replicated traffic as the to-be-detected traffic.

18. The apparatus according to claim 17, wherein, the to-be-detected traffic acquisition module further comprises: The identification information determination unit is configured to determine the identification information of the target detection application; The traffic filtering unit is configured to filter the replicated traffic based on the identification information to obtain the to-be-detected traffic.

19. The apparatus according to claim 18, wherein, the data determination module comprises: The target network intrusion detection rule determination unit is configured to determine a target network intrusion detection rule corresponding to the target detection application based on preset mapping information, and the preset mapping information represents a preset relationship between multiple detection applications and corresponding network intrusion detection rules; The network intrusion detection rule determination unit is configured to use the corresponding target network intrusion detection rule as the multiple network intrusion detection rules.

20. The apparatus according to any one of claims 12 to 16, wherein, the apparatus further comprises: The decoding processing module is configured to perform decoding processing on the filtered traffic data to obtain decoded traffic data; The first network intrusion detection module is further configured to perform network intrusion detection on the decoded traffic data based on the multiple network intrusion detection rules and the detection sorting information, so as to obtain a target intrusion detection result.

21. The apparatus according to any one of claims 12 to 16, wherein, the first network intrusion detection module includes: a network intrusion detection rule traversal unit, configured to traverse the multiple network intrusion detection rules according to the detection sorting information; a network intrusion detection unit, configured to, when any network intrusion detection rule is traversed, perform network intrusion detection on the traffic to be detected by using the currently traversed network intrusion detection rule, so as to obtain a network intrusion detection result corresponding to the currently traversed network intrusion detection rule; a target intrusion detection result determination unit, configured to use the network intrusion detection result obtained during the traversal process as the target intrusion detection result.

22. The apparatus according to claim 21, wherein, when the currently traversed network intrusion detection rule includes a target rule for performing network intrusion detection on target data within a preset time period, the network intrusion detection unit includes: a target data acquisition unit, configured to acquire the target data within the preset time period from the traffic to be detected; a network intrusion detection subunit, configured to perform network intrusion detection on the target data based on the target rule, so as to obtain a network intrusion detection result corresponding to the target rule.

23. A network intrusion detection device, wherein, the device includes a processor and a memory, and at least one instruction or at least one program segment is stored in the memory, and the at least one instruction or the at least one program segment is loaded and executed by the processor to implement the network intrusion detection method according to any one of claims 1 to 11.

24. A computer-readable storage medium, wherein, at least one instruction or at least one program segment is stored in the storage medium, and the at least one instruction or the at least one program segment is loaded and executed by a processor to implement the network intrusion detection method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • System and method for providing security to in-vehicle network

    CN111434090A

  • Detecting malicious activity

    US20080022407A1