Abnormal device recognition method, device, equipment, medium and program product

By performing feature extraction and timing prediction of network traffic data, combined with whitelist and blacklist mechanisms, intelligent identification and real-time monitoring of abnormal devices are achieved, and the problems of labor-intensive and poor timeliness in the existing technology are solved, and the intelligence and timeliness of abnormal device discovery are improved.

CN115426161BActive Publication Date: 2025-06-20INDUSTRIAL AND COMMERCIAL BANK OF CHINA +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211050202.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-30
Publication Date
2025-06-20
Estimated Expiration
2042-08-30

AI Technical Summary

Technical Problem

When identifying equipment with abnormal network traffic, the existing technology requires professional experience and a lot of manpower, and can only effectively prevent equipment that has been accessed abnormally in the early stage, and cannot actively discover equipment that has been invaded for the first time, which is poor in time.

Method used

By extracting the network traffic data of the device to be detected, it is determined whether it belongs to a whitelist or a blacklist. If it does not, extract the abnormal identification feature information and input the network traffic timing prediction model to predict the network traffic timing results, calculate the similarity with the observed value. When the similarity is less than the threshold, it is determined that the device is a suspicious abnormal device and add it to the blacklist to block access.

Benefits of technology

It improves the intelligence and timeliness of abnormal equipment discovery, and can efficiently and intelligently monitor the equipment status in real time, detect abnormalities in a timely manner, reduce data processing volume, and improve monitoring efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115426161B_ABST
    Figure CN115426161B_ABST
Patent Text Reader

Abstract

The present disclosure provides an abnormal device recognition method, which can be applied to the field of artificial intelligence technology. The method includes: extracting network traffic data corresponding to a device to be detected; determining whether the i-th device belongs to a whitelist device or a blacklist device; when the i-th device does not belong to the whitelist device or the blacklist device, extracting abnormal recognition feature information corresponding to the i-th device based on the network traffic data corresponding to the i-th device; inputting the abnormal recognition feature information corresponding to the i-th device into a network traffic time series prediction model to obtain a network traffic time series prediction result; and calculating the similarity between the network traffic time series prediction result and the network traffic observation value at the same time point. When the number of time points at which the similarity is less than a first threshold is greater than a second threshold, it is determined that the i-th device is a suspicious abnormal device. The present disclosure also provides an abnormal device recognition apparatus, device, storage medium, and program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of artificial intelligence technology or the financial field, and specifically, to a method, apparatus, device, medium, and program product for identifying abnormal devices. Background Art

[0002] With the development of big data technology, network traffic analysis technology has received increasing attention. In the field of enterprise intranet security control, by analyzing network traffic data, it is possible to obtain which devices have accessed the enterprise intranet, whether it is a normal access or a suspected intrusion. Network traffic analysis has gradually developed into an important technical means for enterprise intranet access control. Currently, the methods for identifying network traffic anomalies mainly involve statistical analysis, visualization, and post-audit monitoring of the captured network traffic data to discover the abnormal access history records of suspicious devices. When the device accesses again, it is blocked.

[0003] In the process of implementing the concept of the present disclosure, the inventors found that there are at least the following problems in the prior art:

[0004] 1. Discovering abnormal access or devices suspected of intrusion through post-event statistics of historical data requires professional experience and a large amount of manpower.

[0005] 2. Based on historical data analysis, it can only effectively prevent devices that have accessed abnormally in the early stage, and cannot actively discover devices that have been intruded for the first time.

[0006] 3. The method based on post-audit has poor timeliness in discovering abnormal devices. Summary of the Invention

[0007] In view of the above problems, embodiments of the present disclosure provide a method, apparatus, device, medium, and program product for identifying abnormal devices, which improve the intelligence and timeliness of discovering abnormal devices.

[0008] According to a first aspect of the present disclosure, an abnormal device identification method is provided, including: extracting network traffic data corresponding to a device to be detected, where the number of devices to be detected is m, and m is an integer greater than or equal to 1; determining whether the i-th device belongs to a whitelist device or a blacklist device, where i satisfies 1 ≤ i ≤ m and i is an integer; when the i-th device does not belong to a whitelist device or a blacklist device, extracting abnormal identification feature information corresponding to the i-th device based on the network traffic data corresponding to the i-th device; inputting the abnormal identification feature information corresponding to the i-th device into a network traffic time series prediction model to obtain a network traffic time series prediction result, where the network traffic time series prediction result includes prediction results corresponding to n time points, and n is an integer greater than or equal to 2; and calculating the similarity between the network traffic time series prediction result and the network traffic observation value at the same time point, and when the number of time points where the similarity is less than a first threshold is greater than a second threshold, determining that the i-th device is a suspicious abnormal device.

[0009] According to an embodiment of the present disclosure, after determining that the i-th device is a suspicious abnormal device, the method further includes: adding the i-th device to the blacklist to block device access.

[0010] According to an embodiment of the present disclosure, when the i-th device belongs to a whitelist device, determining that the i-th device is a normal device and allowing device access; and / or, when the i-th device belongs to a blacklist device, determining that the i-th device is an abnormal device and blocking device access.

[0011] According to an embodiment of the present disclosure, the network traffic data includes access time information, access target information, and access target data packet information; and / or, the abnormal identification feature information includes: access target information and access target data packet information.

[0012] According to an embodiment of the present disclosure, the similarity between the network traffic time series prediction result and the network traffic observation value at the same time point is calculated based on the cosine similarity algorithm.

[0013] According to an embodiment of the present disclosure, the network traffic time series prediction model is trained based on a long short-term memory neural network, where hyperparameters in the training process are adjusted based on the AutoML model parameter tuning method.

[0014] According to an embodiment of the present disclosure, the hyperparameters adjusted based on the AutoML model parameter tuning method include the number of layers of the long short-term memory neural network and the number of model training iterations.

[0015] The second aspect of the present disclosure provides an anomaly recognition device, including: a data acquisition module configured to extract network traffic data corresponding to a device to be detected, where the number of devices to be detected is m, and m is an integer greater than or equal to 1; a judgment module configured to judge whether the i-th device belongs to a whitelist device or a blacklist device, where i satisfies 1 ≤ i ≤ m and i is an integer; a feature extraction module configured to, when the i-th device does not belong to a whitelist device or a blacklist device, extract anomaly recognition feature information corresponding to the i-th device based on the network traffic data corresponding to the i-th device; a model prediction module configured to input the anomaly recognition feature information corresponding to the i-th device into a network traffic time series prediction model to obtain a network traffic time series prediction result, where the network traffic time series prediction result includes prediction results corresponding to n time points, and n is an integer greater than or equal to 2; and an anomaly determination module configured to calculate the similarity between the network traffic time series prediction result and the network traffic observation value at the same time point, and when the number of time points with a similarity less than a first threshold is greater than a second threshold, determine that the i-th device is a suspicious anomaly device.

[0016] According to an embodiment of the present disclosure, the anomaly recognition device may further include a result processing module. Among them, the result processing module is configured to add the i-th device to the blacklist when it is determined that the i-th device is a suspicious anomaly device.

[0017] According to an embodiment of the present disclosure, the anomaly recognition device may further include a blocking module. Among them, the blocking module is configured to, or after adding the i-th device to the blacklist, block device access. It can be understood that when it is determined that the i-th device itself is a blacklist device, the blocking module 470 may also be activated to determine that the i-th device is an abnormal device and block device access.

[0018] According to an embodiment of the present disclosure, the anomaly recognition device may further include a release module, and the release module is configured to determine that the i-th device is a normal device and allow device access when the i-th device belongs to a whitelist device.

[0019] The third aspect of the present disclosure provides an electronic device, including: one or more processors; a memory for storing one or more programs, where, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above-mentioned anomaly recognition method.

[0020] The fourth aspect of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the above-mentioned anomaly recognition method.

[0021] The fifth aspect of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above-mentioned anomaly recognition method is implemented.

[0022] The method provided by the embodiments of the present disclosure predicts the time series prediction value of the network traffic of a device at a certain point in time based on a network traffic time series prediction model, compares it with the true observed value at the same point in time, and determines whether the predicted network traffic at this point is abnormal based on similarity calculation. Further, it determines whether the device is abnormal by measuring the abnormal conditions of the network traffic at multiple points in time. The method provided by the embodiments of the present disclosure can efficiently and intelligently monitor the device status in real time and detect abnormalities in a timely manner. And by setting blacklist devices / whitelist devices, the amount of data processing in the abnormal device determination process can be reduced, and the monitoring efficiency can be improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above content and other objects, features and advantages of the present disclosure will become clearer. In the drawings:

[0024] Figure 1 Schematically shows an application scenario diagram of an abnormal device identification method, device, equipment, medium and program product according to an embodiment of the present disclosure.

[0025] Figure 2 Schematically shows a flowchart of an abnormal device identification method according to an embodiment of the present disclosure.

[0026] Figure 3 Schematically shows a flowchart of an abnormal device identification method according to some other embodiments of the present disclosure.

[0027] Figure 4 Exemplarily shows the working principle diagram of a long short-term memory neural network.

[0028] Figure 5 Schematically shows a structural block diagram of an abnormal identification device according to an embodiment of the present disclosure.

[0029] Figure 6 Schematically shows a structural block diagram of an abnormal identification device according to some other embodiments of the present disclosure.

[0030] Figure 7 Schematically shows a structural block diagram of an abnormal identification device according to some other embodiments of the present disclosure.

[0031] Figure 8 Schematically shows a structural block diagram of an abnormal identification device according to some other embodiments of the present disclosure.

[0032] Figure 9 Schematically shows a block diagram of an electronic device suitable for implementing an abnormal device identification method according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, numerous specific details are set forth in order to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is obvious that one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.

[0034] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0035] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0036] In the case of using expressions such as "at least one of A, B, and C, etc.", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).

[0037] Before revealing the embodiments of the present disclosure in detail, the key technical terms to be used in the present disclosure will be explained one by one:

[0038] LSTM: It is a neural network in deep learning, and its full name is Long Short-Term Memory Neural Network. LSTM is a time-recurrent neural network, which is specially designed to solve the long-term dependence problem existing in general RNNs (Recurrent Neural Networks). LSTM is often used for time series-related predictions and has good effects.

[0039] Cosine similarity: Also known as cosine similarity, it evaluates the similarity between two vectors by calculating the cosine value of the included angle between them.

[0040] Network traffic: It is network-related data collected by network traffic collection devices deployed on switches.

[0041] Device fingerprint: It refers to the device features or unique device identifiers that can be used to uniquely identify the device.

[0042] Hyperparameters: Parameters that are set in advance before machine learning and are not obtained through training. For example, the number of trees and depth, the number of layers of a neural network, etc. all fall within the category of hyperparameters.

[0043] With the development of big data technology, network traffic analysis technology has received increasing attention. In the field of enterprise intranet security control, by analyzing network traffic data, it is possible to obtain which devices have accessed the enterprise intranet, whether it is a normal access or a suspected intrusion. Network traffic analysis has gradually developed into an important technical means for enterprise intranet access control. Currently, the methods for identifying network traffic anomalies mainly involve statistical analysis, visualization, and post-audit monitoring of the captured network traffic data to discover the abnormal access history records of suspicious devices. When the device accesses again, it is blocked. However, the above methods in the existing technology have the following disadvantages: Discovering abnormal access or devices suspected of intrusion through post-facto statistics of historical data requires a lot of expert experience and a large amount of manpower; Analyzing through the abnormal access history records of suspicious devices can only effectively block devices that have accessed abnormally in the early stage and cannot actively discover devices that are intruded for the first time; The statistical method based on historical data has poor timeliness in discovering abnormal devices.

[0044] In view of the above problems in the existing technology, embodiments of the present disclosure provide a method for identifying abnormal devices, including: extracting network traffic data corresponding to a device to be detected, where the number of devices to be detected is m, and m is an integer greater than or equal to 1; determining whether the i-th device belongs to a whitelist device or a blacklist device, where i satisfies 1 ≤ i ≤ m and i is an integer; when the i-th device does not belong to a whitelist device or a blacklist device, extracting abnormal identification feature information corresponding to the i-th device based on the network traffic data corresponding to the i-th device; inputting the abnormal identification feature information corresponding to the i-th device into a network traffic time series prediction model to obtain a network traffic time series prediction result, where the network traffic time series prediction result includes prediction results corresponding to n time points, and n is an integer greater than or equal to 2; and calculating the similarity between the network traffic time series prediction result and the network traffic observation value at the same time point, and when the number of time points where the similarity is less than a first threshold is greater than a second threshold, determining that the i-th device is a suspicious abnormal device.

[0045] The method provided by the embodiments of the present disclosure predicts the time-series prediction value of the network traffic of a device based on a network traffic time-series prediction model, compares it with the true observed value at the same time point, and determines whether the predicted network traffic at this time point is abnormal based on the similarity calculation. Further, it determines whether the device is abnormal by measuring the abnormal conditions of the network traffic at multiple time points. The method provided by the embodiments of the present disclosure can efficiently and intelligently monitor the device status in real time and detect abnormalities in a timely manner. And by setting blacklist devices / whitelist devices, the data processing volume in the process of determining abnormal devices can be reduced, and the monitoring efficiency can be improved.

[0046] It should be noted that the abnormal device identification method, device, equipment, medium and program product provided by the embodiments of the present disclosure can be used in the related aspects of artificial intelligence technology for device abnormal traffic identification, and can also be used in a variety of fields other than artificial intelligence technology, such as the financial field, etc. The application fields of the abnormal device identification method, device, equipment, medium and program product provided by the embodiments of the present disclosure are not limited.

[0047] The above operations for achieving at least one object of the present disclosure will be described below in conjunction with the accompanying drawings and their explanatory texts.

[0048] Figure 1 Schematically shows an application scenario diagram of an abnormal device identification method, device, equipment, medium and program product according to an embodiment of the present disclosure.

[0049] As Figure 1 shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103. The network 104 is a medium for providing a communication link between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links or fiber optic cables, etc.

[0050] Users can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 101, 102, 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0051] The terminal devices 101, 102, 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.

[0052] Server 105 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using terminal devices 101, 102, and 103. The background management server can analyze and process data such as user requests received, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0053] It should be noted that the abnormal device identification method provided by the embodiments of the present disclosure can generally be executed by server 105. Correspondingly, the abnormal device identification device provided by the embodiments of the present disclosure can generally be set in server 105. The abnormal device identification method provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105. Correspondingly, the abnormal device identification device provided by the embodiments of the present disclosure can also be set in a server or a server cluster different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105.

[0054] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in

[0055] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 1 The following will be based on Figures 2 to 4 the described scenario, and will describe in detail the abnormal device identification method of the disclosed embodiments through

[0056] Figure 2 FIG. schematically shows a flowchart of an abnormal device identification method according to an embodiment of the present disclosure.

[0057] As Figure 2 shown, the abnormal device identification method of this embodiment at least includes operation S210 to operation S250. This abnormal device identification can be executed by a processor or by any electronic device including a processor.

[0058] In operation S210, network traffic data corresponding to the device to be detected is extracted, and the number of devices to be detected is m, where m is an integer greater than or equal to 1.

[0059] According to an embodiment of the present disclosure, it can be understood that there may be one or more devices to be detected. The method according to the embodiment of the present disclosure can be applied to detect multiple devices to be detected within a range at the same time. Among them, the network traffic data can be collected in real time through the data interface provided by the network traffic collection device deployed on the switch and stored in the database for network traffic time series prediction. By formatting the network traffic data, the network traffic data corresponding to each device to be detected can be extracted. For example, based on device fingerprint information, such as IP information, MAC information, etc., the network traffic data generated by the device within a specified time range can be obtained.

[0060] In operation S220, it is determined whether the i-th device belongs to the whitelist device or the blacklist device, where i satisfies 1 ≤ i ≤ m and i is an integer.

[0061] According to an embodiment of the present disclosure, to reduce the data processing volume and improve the efficiency of abnormal device monitoring, a whitelist device list and a blacklist device list can be set. For example, a device fingerprint library can be configured, and the whitelist device list and the blacklist device list information are stored in the device fingerprint library. When the device to be detected belongs to the whitelist device list or the blacklist device list, no further abnormal identification is required. In the embodiment of the present disclosure, the whitelist device list may include routine detection and scanning devices. For example, devices that are rarely used usually but have a large amount of network traffic data passing through within a specific time range. If a whitelist device is included in the device list to be detected, false alarms may occur and detection resources may be wasted. A whitelist device list can be set, and no abnormal monitoring and analysis are performed on the devices therein, reducing the data processing volume and saving resources. The blacklist device list may include devices with confirmed abnormal access, and manual monitoring and investigation can be separately set for the devices in the blacklist device list to reduce the data processing volume of the network traffic time series prediction model.

[0062] It should be understood that operation S220 does not necessarily need to be executed after operation S210. For example, operation S220 can also be executed while operation S210 is being executed, or operation S220 can be executed before operation S210.

[0063] When the i-th device does not belong to the whitelist device or the blacklist device, operation S230 is executed.

[0064] In operation S230, the abnormal identification feature information corresponding to the i-th device is extracted based on the network traffic data corresponding to the i-th device.

[0065] According to an embodiment of the present disclosure, the abnormal recognition feature information is obtained from network traffic data. A feature engineering method can be used to extract the feature information for inputting into the model, that is, the abnormal recognition feature information corresponding to the i-th device, after preprocessing means such as data cleaning on the original network traffic data.

[0066] In some embodiments, the network traffic data includes access time information, access target information, and access target packet information. Further, in some embodiments, the abnormal recognition feature information includes access target information and access target packet information.

[0067] According to an embodiment of the present disclosure, devices can be identified based on device fingerprint identifiers, and the number of packets of access targets for each device is statistically counted at a preset time interval to construct an abnormal recognition feature information vector X. Whether the change trend of the number of packets is abnormal can be used to clearly judge abnormal or malicious traffic. Among them, the preset time interval can be flexibly adjusted based on device access conditions and monitoring requirements. In some preferred embodiments, the preset time interval can be set to 5 - 20 minutes. After testing, the above time interval period has a good abnormal monitoring and recognition effect.

[0068] In a specific example, the number of packets of the device to be detected accessing different destination IPs is statistically counted at a 5 - minute time interval, and an abnormal recognition feature information vector X is constructed. For each device, the constructed feature space is shown in Table 1:

[0069] Table 1

[0070]

[0071] In operation S240, the abnormal recognition feature information corresponding to the i-th device is input into the network traffic time series prediction model to obtain a network traffic time series prediction result, and the network traffic time series prediction result includes prediction results corresponding to n time points, where n is an integer greater than or equal to 2.

[0072] In operation S250, the similarity between the network traffic time series prediction result and the network traffic observation value at the same time point is calculated. When the number of time points where the similarity is less than the first threshold is greater than the second threshold, it is determined that the i-th device is a suspicious abnormal device.

[0073] According to an embodiment of the present disclosure, since a single measurement result may be misjudged, the time-series prediction results of network traffic at different time points can be measured and compared with the network traffic observation values at the same time points to calculate the similarity between the two, so as to determine whether the access behavior at this time point is abnormal. During the similarity comparison process, a first threshold can be set as a measure of whether the access behavior is abnormal. When the similarity is less than the first threshold, it indicates that the current access behavior is abnormal. Exemplarily, the first threshold can be set based on the criteria and accuracy requirements for anomaly recognition. Preferably, the first threshold can be set to 50%, 55%, 60%, 65%, 70%, 75%, etc. In the embodiments of the present disclosure, after obtaining the similarity calculation results at multiple time points, it is possible to determine whether the device is abnormal based on a preset rule. For example, a second threshold can be preset as a measure of the number of monitored time points. When the number of time points with abnormal access behavior is greater than the second threshold, the device is judged to be suspicious. For example, the access situation of the device to be detected within a preset time range can be monitored at a preset time interval. When the number of time points with abnormal access behavior exceeds the second threshold, the device is judged to be suspicious. Exemplarily, with a 5-minute time interval, detecting the device to be detected in a day, 288 time-point similarity monitoring results can be obtained. The second threshold number can be preset to 5. Then, when the number of time points with abnormal access behavior is greater than 5, it is determined that the device is abnormal.

[0074] It should be understood that when it is determined that the i-th device belongs to the whitelist device, operation S260 is executed.

[0075] In operation S230, it is determined that the i-th device is a normal device, and the device is allowed to access.

[0076] Among them, when it is determined that the i-th device belongs to the blacklist device, operation S270 is executed.

[0077] In operation S240, it is determined that the i-th device is an abnormal device, and the device access is blocked.

[0078] According to an embodiment of the present disclosure, the cosine similarity algorithm can be used to calculate the similarity between the time-series prediction result of the network traffic and the network traffic observation value at the same time point. For example, at 00:40, the actually observed feature vector is [26, 36, 28, 29], and the predicted vector data at 00:40 predicted by the network traffic time-series prediction model is [1, 0, 0, 1]. Based on the cosine similarity calculation formula, the similarity between the actually observed feature vector and the predicted vector predicted by the network traffic time-series prediction model is calculated. The cosine similarity between the two is relatively low, less than 50%, then it is considered that the device access is abnormal.

[0079] Figure 3 The flowchart of the abnormal device recognition method according to some other embodiments of the present disclosure is schematically shown.

[0080] As Figure 3 shown, in addition to the same processes as the abnormal device recognition method of the Figure 2 embodiment, the abnormal device recognition method of this embodiment may further include operation S280.

[0081] In operation S280, after determining that the i-th device is a suspicious abnormal device, add the i-th device to the blacklist to block device access.

[0082] In the embodiments of the present disclosure, the network traffic time series prediction model is trained based on a long short-term memory neural network, and among them, the hyperparameters in the training process are adjusted based on the AutoML model parameter tuning method.

[0083] The long short-term memory neural network (Long Short-Term Memory, abbreviated as LSTM) is a type of time-recurrent neural network, which is specifically designed to solve the long-term dependence problem existing in general RNNs (recurrent neural networks). LSTM consists of memory cells, forget gates, input gates, and output gates. Among them, the memory cells are responsible for storing historical information, recording and updating historical information through a state parameter, and the three gate structures determine the selection of information through the Sigmoid function, thus acting on the memory cells. The forget gate is used to selectively forget redundant or secondary memories, the input gate determines what values need to be updated, and the output gate determines which part of the cell state is output.

[0084] In the embodiments of the present disclosure, the basic process of establishing a network traffic time series prediction model based on LSTM is as follows:

[0085] Assume that the format of the original time series data is: [1, 2, 3, 4, 5, 6, 7]

[0086] The network traffic time series prediction model established based on LSTM is a model that calculates the time series prediction value at the (n + 1)-th time point based on n steps. Thus, the training sample feature X vector and the corresponding time series prediction label (Lable) Y can be obtained.

[0087] Exemplary sample data feature vectors and labels are as follows:

[0088]

[0089] The network traffic time series prediction model of the embodiments of the present disclosure can be constructed using the LSTM algorithm based on the collected sample data. Among them, to ensure the accuracy of the model, sample data of abnormal recognition feature information within a certain time range can be collected. In one example, the access target information and the access target data packet volume statistically counted at a sampling frequency of every 5 minutes within one month can be used as sample data to construct the model.

[0090] Figure 4 Exemplarily shows the working principle diagram of the long short-term memory neural network.

[0091] Such as Figure 4 , C (t) The coefficient that determines how much memory from the current moment is retained to the next moment, h (t) Is the output value of the LSTM at the current moment, C (t-1) The coefficient that determines how much memory from the previous moment is retained to the current moment, h (t-1) Is the output value of the LSTM at the previous moment, x (t-1) Is the input of the training sample at sequence index t-1, W i Is the weight matrix of the input gate, corresponding to the input variable X, W f Is the weight matrix of the forget gate, corresponding to the input variable X, W o Is the weight matrix of the output gate, corresponding to the input variable X, W c Cell state update weight matrix, corresponding to the input variable X, σ is the activation function. It can be calculated based on the forward propagation algorithm or the backpropagation algorithm. The embodiments of the present disclosure use the backpropagation algorithm to update the model parameters. Among them, the loss function is defined as the mean square error function, and the gradient descent method is used to continuously update the weights until the training cutoff condition, such as a preset number of iterations or model, to obtain the network traffic time series prediction model.

[0092] In the embodiments of the present disclosure, the hyperparameters in the training process are adjusted based on the AutoML model parameter tuning method. AutoML is an automatic machine learning method that can automate the feature engineering and hyperparameter optimization of machine learning and is a full-pipeline machine learning automation tool. In the embodiments of the present disclosure, to improve the model accuracy and the training speed of the model, the AutoML method can be used to automatically tune the model hyperparameters. Specifically, the initial hyperparameters can be set, and then the initial hyperparameters can be automatically adjusted through methods such as random search and grid search until the hyperparameters when the model accuracy and precision are relatively high are used as the actually determined hyperparameters of the model.

[0093] In some embodiments, the hyperparameters that can be adjusted based on the AutoML model parameter tuning method include the number of layers of the long short-term memory neural network and the number of model training iterations.

[0094] Through the abnormal device recognition method provided by the embodiments of the present disclosure, when recognizing an abnormal device, by using the access timing information of the device itself as the input of the network traffic timing prediction model, a prediction and judgment of future access conditions can be automatically obtained. It is possible to determine in real time whether the network access traffic data generated by the device is an abnormal access, and the timeliness is relatively high. In the preferred model training process, the automatic hyperparameter tuning function of AutoML can be used to automate the hyperparameter tuning. Compared with manual hyperparameter tuning, higher hyperparameter tuning efficiency and model accuracy can be obtained.

[0095] Based on the above abnormal recognition method, an embodiment of the present disclosure further provides an abnormal recognition device. The following will be combined with Figure 5 to describe this device in detail.

[0096] Figure 5 The structural block diagram of the abnormal recognition device according to the embodiment of the present disclosure is schematically shown.

[0097] As Figure 5 shown, the abnormal recognition device 500 of this embodiment includes a data acquisition module 510, a judgment module 520, a feature extraction module 530, a model prediction module 540, and an abnormal determination module 550.

[0098] The data acquisition module 510 is configured to extract network traffic data corresponding to the device to be detected, and the number of devices to be detected is m, where m is an integer greater than or equal to 1.

[0099] The judgment module 520 is configured to judge whether the i-th device belongs to the whitelist device or the blacklist device, where i satisfies 1 ≤ i ≤ m and i is an integer.

[0100] The feature extraction module 530 is configured to, when the i-th device does not belong to the whitelist device or the blacklist device, extract abnormal recognition feature information corresponding to the i-th device based on the network traffic data corresponding to the i-th device.

[0101] The model prediction module 540 is configured to input the abnormal recognition feature information corresponding to the i-th device into the network traffic timing prediction model to obtain a network traffic timing prediction result, and the network traffic timing prediction result includes prediction results corresponding to n time points, where n is an integer greater than or equal to 2.

[0102] The abnormal determination module 550 is configured to calculate the similarity between the network traffic timing prediction result and the network traffic observation value at the same time point. When the number of time points where the similarity is less than the first threshold is greater than the second threshold, it is determined that the i-th device is a suspicious abnormal device.

[0103] Figure 6Schematically shows a structural block diagram of an anomaly recognition device according to other embodiments of the present disclosure.

[0104] As Figure 6 shown, in addition to including a data acquisition module 510, a judgment module 520, a feature extraction module 530, a model prediction module 540, and an anomaly determination module 550, the anomaly recognition device 500 of this embodiment may further include a result processing module 560.

[0105] Among them, the functions of the data acquisition module 510, the judgment module 520, the feature extraction module 530, the model prediction module 540, and the anomaly determination module 550 may be the same as those of the modules in the anomaly recognition device of the Figure 5 shown embodiment, and will not be elaborated here.

[0106] Among them, the result processing module 560 is configured to add the i-th device to the blacklist when it is determined that the i-th device is a suspicious anomaly device.

[0107] Figure 7 Schematically shows a structural block diagram of an anomaly recognition device according to other embodiments of the present disclosure.

[0108] As Figure 7 shown, in addition to including a data acquisition module 510, a judgment module 520, a feature extraction module 530, a model prediction module 540, and an anomaly determination module 550, the anomaly recognition device 500 of this embodiment may further include a blocking module 570.

[0109] Among them, the functions of the data acquisition module 510, the judgment module 520, the feature extraction module 530, the model prediction module 540, and the anomaly determination module 550 may be the same as those of the modules in the anomaly recognition device of the Figure 5 shown embodiment, and will not be elaborated here.

[0110] The blocking module 570 is configured to block device access when the i-th device is added to the blacklist. It can be understood that when it is determined that the i-th device itself is a blacklist device, the blocking module 570 may also be activated to determine that the i-th device is an anomaly device and block device access.

[0111] Figure 8 Schematically shows a structural block diagram of an anomaly recognition device according to other embodiments of the present disclosure.

[0112] As Figure 7 shown, in addition to including a data acquisition module 510, a judgment module 520, a feature extraction module 530, a model prediction module 540, and an anomaly determination module 550, the anomaly recognition device 500 of this embodiment may further include a release module 580.

[0113] Among them, the functions of the data acquisition module 510, the judgment module 520, the feature extraction module 530, the model prediction module 540, and the anomaly determination module 550 can be the same as those of the modules in the anomaly recognition device of the embodiment Figure 5 shown, and will not be elaborated here.

[0114] The release module 580 is configured to determine that the i-th device is a normal device and allow the device to access when the i-th device belongs to the whitelist device.

[0115] According to an embodiment of the present disclosure, any plurality of modules among the data acquisition module 510, the judgment module 520, the feature extraction module 530, the model prediction module 540, the anomaly determination module 550, the result processing module 560, the blocking module 570, and the release module 580 can be combined and implemented in one module, or any one of them can be split into multiple modules. Or, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the data acquisition module 510, the judgment module 520, the feature extraction module 530, the model prediction module 540, the anomaly determination module 550, the result processing module 560, the blocking module 570, and the release module 580 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or can be implemented by any other reasonable means such as integrating or packaging the circuit, etc., in hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Or, at least one of the data acquisition module 510, the judgment module 520, the feature extraction module 530, the model prediction module 540, the anomaly determination module 550, the result processing module 560, the blocking module 570, and the release module 580 can be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding functions can be executed.

[0116] Figure 9 A block diagram of an electronic device suitable for implementing the abnormal device recognition method according to an embodiment of the present disclosure is schematically shown.

[0117] As Figure 9As shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage section 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 901 may also include on-board memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0118] In the RAM 903, various programs and data required for the operation of the electronic device 900 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method flow according to an embodiment of the present disclosure by executing the program in the ROM 902 and / or the RAM 903. It should be noted that the program may also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 may also perform various operations of the method flow according to an embodiment of the present disclosure by executing the program stored in the one or more memories.

[0119] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, and the input / output (I / O) interface 905 is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the I / O interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed so that a computer program read therefrom can be installed into the storage portion 908 as needed.

[0120] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to an embodiment of the present disclosure is implemented.

[0121] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, which may include, for example, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the above-described ROM 902 and / or RAM 903 and / or one or more memories other than ROM 902 and RAM 903.

[0122] An embodiment of the present disclosure further includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to cause the computer system to implement the method provided by the embodiment of the present disclosure.

[0123] When the computer program is executed by the processor 901, it executes the above functions defined in the system / apparatus of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. may be implemented by computer program modules.

[0124] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and be downloaded and installed through the communication part 909, and / or be installed from the removable medium 911. The program code included in the computer program may be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0125] In such an embodiment, the computer program may be downloaded and installed from the network through the communication part 909, and / or be installed from the removable medium 911. When the computer program is executed by the processor 901, it executes the above functions defined in the system of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. may be implemented by computer program modules.

[0126] According to embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. The programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).

[0127] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0128] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined or / and combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.

[0129] The embodiments of the present disclosure have been described above. However, these embodiments are merely for illustrative purposes and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.

Claims

1. An abnormal device recognition method, characterized in that, Including: Extracting network traffic data corresponding to the device to be detected, where the number of devices to be detected is m, and m is an integer greater than or equal to 1; Configuring a device fingerprint library, storing a whitelist device list and blacklist device list information in the device fingerprint library, and determining whether the i-th device belongs to the whitelist device or the blacklist device, where i satisfies 1 ≤ i ≤ m and i is an integer; When the i-th device does not belong to the whitelist device or the blacklist device, extracting abnormal recognition feature information corresponding to the i-th device based on the network traffic data corresponding to the i-th device; Inputting the abnormal recognition feature information corresponding to the i-th device into a network traffic time series prediction model to obtain a network traffic time series prediction result, where the network traffic time series prediction result includes prediction results corresponding to n time points, and n is an integer greater than or equal to 2; among them, the network traffic time series prediction model is trained based on a long short-term memory neural network, and the hyperparameters during the training process are adjusted based on the AutoML model parameter tuning method; and Calculating the similarity between the network traffic time series prediction result and the network traffic observation value at the same time point, and when the number of time points with a similarity less than the first threshold is greater than the second threshold, determining that the i-th device is a suspicious abnormal device; After determining that the i-th device is a suspicious abnormal device, the method further includes: adding the i-th device to the blacklist and blocking device access.

2. A method according to claim 1, wherein, The method further includes: When the i-th device belongs to the whitelist device, determining that the i-th device is a normal device and allowing device access; And / or When the i-th device belongs to the blacklist device, determining that the i-th device is an abnormal device and blocking device access.

3. A method according to claim 1, wherein, The network traffic data includes access time information, access target information, and access target data packet information; And / or, the abnormal recognition feature information includes: access target information and access target data packet information.

4. A method according to claim 1, wherein, Calculating the similarity between the network traffic time series prediction result and the network traffic observation value at the same time point based on the cosine similarity algorithm.

5. A method according to claim 4, wherein, The hyperparameters adjusted based on the AutoML model parameter tuning method include the number of layers of the long short-term memory neural network and the number of model training iterations.

6. An abnormal recognition device, comprising: A data acquisition module configured to extract network traffic data corresponding to the device to be detected, where the number of devices to be detected is m, and m is an integer greater than or equal to 1; A judgment module configured to configure a device fingerprint library, store a whitelist device list and blacklist device list information in the device fingerprint library, and judge whether the i-th device belongs to the whitelist device or the blacklist device, where i satisfies 1 ≤ i ≤ m and i is an integer; A feature extraction module configured to, when the i-th device does not belong to the whitelist device or the blacklist device, extract abnormal recognition feature information corresponding to the i-th device based on the network traffic data corresponding to the i-th device; A model prediction module, configured to input the abnormal identification feature information corresponding to the i-th device into a network traffic time series prediction model to obtain a network traffic time series prediction result, where the network traffic time series prediction result includes prediction results corresponding to n time points, and n is an integer greater than or equal to 2; wherein, the network traffic time series prediction model is trained based on a long short-term memory neural network, and wherein hyperparameters in the training process are adjusted based on the AutoML model parameter tuning method; and An abnormal determination module, configured to calculate the similarity between the network traffic time series prediction result and the network traffic observation value at the same time point, and determine that the i-th device is a suspicious abnormal device when the number of time points with a similarity less than a first threshold is greater than a second threshold; A result processing module, configured to add the i-th device to a blacklist when it is determined that the i-th device is a suspicious abnormal device; A blocking module, configured to block device access after adding the i-th device to the blacklist; 7. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 5.

8. A computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor executes the method according to any one of claims 1 to 5.

9. A computer program product, comprising a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Abnormal flow detection system and abnormal flow detection method based on service model

    CN108289088A

  • Abnormal flow monitoring method, device and apparatus and storage medium

    CN110839016A