A method and system for detecting abnormality of power terminals based on flow baseline
By adopting a multi-dimensional detection method based on traffic baseline on smart power terminals, network traffic data is analyzed and analyzed, and abnormal detection is carried out from the dimensions of traffic, protocol and application layer function codes, the limitations of abnormal detection of smart power terminals in the prior art are solved, and more efficient and accurate detection effects are achieved.
Patent Information
- Application Number
- CN202210919916.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-01
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-08-01
AI Technical Summary
The prior art has limitations in the detection of abnormalities of smart power terminals, and it is difficult to effectively detect abnormal behaviors of power terminals, especially under the unique network regulations and diversified behaviors of power terminals.
A multi-dimensional detection method based on traffic baseline is adopted to collect and parse network traffic data of power terminals, abnormal detection is performed from the dimensions of traffic, protocol and application layer function codes, and the final abnormal detection result is calculated based on the storage of the big data platform and structured database.
It realizes comprehensive and accurate detection of network traffic data of power terminals, improves the accuracy and comprehensiveness of abnormal detection, and provides users with more reliable security guarantees.
Smart Images

Figure CN115473671B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power terminal detection, and in particular to a method and system for detecting power terminal anomalies based on a flow baseline. Background Art
[0002] With the advent of 5G technology and the Internet of Everything, more and more IoT devices are connected to the network, and smart power terminals are one of them. After hundreds of millions of smart power terminals are connected to the network, how to ensure the security of these smart power terminals is an urgent problem that needs to be solved. There are currently many anomaly detection methods for traditional Internet terminals, such as intelligence-based terminal anomaly detection, rule-based terminal anomaly detection, behavior-based terminal anomaly detection, etc. Most of these detection methods are based on Internet terminals and Internet protocols, and have more or less certain limitations.
[0003] The intelligence-based terminal anomaly detection method is based on the threat intelligence black and white lists to detect malicious IPs, malicious domain names, malicious URLs, etc. Although the detection efficiency is very high, there is less exclusive threat intelligence related to power terminals, so this method is difficult to produce good results in power terminal anomaly detection.
[0004] The rule-based terminal anomaly detection method is based on commonly used Internet attack detection, such as: detection scanning, password cracking, vulnerability exploitation, etc. From the detection dimension, although this type of detection can produce certain effects in IoT power terminals, such as detection of weak login passwords, detection of sensitive data leakage, etc., both the detection rules and the types that can be detected are relatively limited. Therefore, this type of detection is also relatively limited in its ability to detect anomalies in power terminals.
[0005] The behavior-based terminal anomaly detection method is based on terminal behavior. The behavior of these terminals is first stored and recorded, and these behaviors are analyzed and counted through analytical statistical algorithms. The existing behavior of the terminal is compared with the analytical statistical results to mine the abnormal behavior of the terminal. Although this method can discover the abnormal behavior of some terminals, it is difficult to use a unified method for statistical analysis and detection because the behavior of each power terminal is different and varied. Therefore, this method also has great difficulty in detecting power terminal anomalies. Summary of the invention
[0006] The present invention provides a method and system for detecting anomalies in power terminals based on flow baselines, which collect all network flow data of power terminals, identify and parse the flow data according to protocols, perform multi-dimensional statistics and anomaly detection from the flow dimension, application layer function code dimension, and protocol dimension of the terminal, and then calculate the anomaly detection in the above dimensions to determine the accuracy of anomaly detection in the power terminal, thereby ensuring the comprehensiveness and accuracy of the terminal flow detection dimension.
[0007] The present invention provides a method for detecting abnormality of a power terminal based on a flow baseline, comprising:
[0008] Collect all network traffic data of the power terminal, and identify and parse the network traffic data according to the protocol; wherein the protocol is a customized data specification used when the network traffic data is transmitted between the power terminal and the upper platform;
[0009] All the power terminal network traffic sessions obtained after parsing are stored in the big data platform and structured database;
[0010] Anomaly detection is performed on the traffic dimension of the power terminal according to the upper and lower limit statistics of the power terminal IP traffic of the time slice to obtain a first anomaly detection result;
[0011] Anomaly detection is performed on the protocol dimension of the power terminal according to the upper and lower limit statistics of the power terminal protocol flow of the time slice to obtain a second anomaly detection result;
[0012] Perform anomaly detection on the application layer function code dimension of the power terminal according to the traffic size statistics of the application layer function code of the power terminal in the time slice, and obtain a third anomaly detection result;
[0013] A final abnormality detection result of the power terminal is calculated according to the first abnormality detection result, the second abnormality detection result and the third abnormality detection result, and a possibility that the power terminal has an abnormality is determined according to the final abnormality detection result.
[0014] Furthermore, the step of collecting all network flow data of the power terminal, identifying and parsing the network flow data according to the protocol, and obtaining the network flow session includes:
[0015] Receive power terminal network traffic mirrored to the network card by aggregation and distribution equipment or switches;
[0016] Collect the data on the network card into the memory, and perform data recognition on the data collected in the memory according to the protocol;
[0017] All the bitstream data stored in the memory is filtered, segmented, combined, and deduplicated according to the IP quintuple information;
[0018] The sorted traffic session data is parsed according to the transport layer protocol, frame data format, and application layer data format specified in the specification to obtain the session record of the network traffic.
[0019] Furthermore, the step of storing all the power terminal network flow sessions obtained after parsing in the big data platform and the structured database includes:
[0020] Temporarily store all received power terminal network traffic sessions in the Kafka message middleware, and generate and consume data through the producer and consumer mode;
[0021] Big data platform storage and structured data storage are performed according to the data format and data volume that need to be stored.
[0022] Furthermore, the step of performing anomaly detection on the flow dimension of the power terminal according to the upper and lower limit statistics of the power terminal IP flow of the time slice to obtain a first anomaly detection result includes:
[0023] A reference duration and a time slice granularity set are selected; wherein the reference duration is greater than or equal to 2 days, and the power terminal flow data within the reference duration is normal data, and the time slice granularity set includes multiple time slices, namely: 1 minute time slice, 5 minute time slice, 10 minute time slice, 30 minute time slice and 60 minute time slice;
[0024] The data at the same time point of each time slice in the reference duration is a data set D = {max, min, med, n}; wherein max represents the maximum value at the same time point on the time slice, min represents the minimum value at the same time point on the time slice, med represents the middle value of all the same time points on the slice, and n represents the number of accumulated data;
[0025] The set of normal data of the power terminal IP at a time point in the past is D = {max, min, med, n}. The data at the time point obtained according to the slice granularity is d1, and d1 is equal to the sum of all session record traffic in the slice;
[0026] The first abnormality detection result s1 is calculated based on d1.
[0027] Furthermore, the step of calculating the first abnormality detection result s1 according to d1 includes:
[0028] When max=min=med, When s1=0, n=n+1; when s1>0, the user's instruction to determine whether d1 is added to the D data set is received; wherein s1 is the first abnormality detection result;
[0029] When d1>max, When s1>1, s1=1;
[0030] When d1<min, When s1>1, s1=1;
[0031] When med≤d1≤max, Among them, med and n in D are recalculated, and the calculation of med is: when n is an even number, When n is an odd number, The calculation of n is: n=n+1;
[0032] When min≤d1≤med, Among them, med and n in D are recalculated, and the calculation of med is: when n is an even number, When n is an odd number, The calculation of n is: n=n+1;
[0033] When 0.8<s1≤1, the receiving user determines whether the traffic terminal point is added to D. If it is added to D, the max or min in D is modified, and the med and n values are modified in the same manner as when med≤d1≤max or min≤d1≤med.
[0034] Furthermore, the step of performing anomaly detection on the application layer function code dimension of the power terminal according to the traffic size statistics of the application layer function code of the power terminal of the time slice to obtain a third anomaly detection result includes:
[0035] A reference duration and a time slice granularity set are selected; wherein the reference duration is greater than or equal to 1 hour, and the flow size of each time of the power terminal application layer function code within the reference duration is normal data, and the time slice granularity set includes multiple time slice methods, namely: time slice by 1 hour, time slice by 1 day, time slice by 1 week, and time slice by 1 month;
[0036] In the benchmark duration, the data in each slice time is a two-dimensional data set D = {D1, D2, D3, ...}, Dn = {starttime, endtime, fcode, n, avg}; where starttime represents the start statistical time of the slice, endtime represents the end statistical time of the slice, fcode represents the application layer function code number, n represents the number of times the application layer function code is generated in the slice time, and avg represents the average traffic of each access of the application layer function code in the slice time;
[0037] The specific value in the data set of each function code per day is calculated according to the time slice method in the time slice granularity set; wherein the data set of each function code per day is Dn={starttime, endtime, fcode, n, avg}, and the calculation formula of avg is: avg i Indicates the average traffic volume of each access of the same application layer function code every hour from 0 to 24 hours, n i Indicates the number of accesses to the same application layer function code every hour from 0 to 24 hours;
[0038] Obtain the flow data size d2 accessed by the application layer function code of the power terminal, find the data set Dn corresponding to the application layer function code from the slice order of month, week, day, and hour, and compare the flow size d2 with the avg in the same application layer function code Dn with the largest slice granularity;
[0039] like Then the slice size s=0; if or Then the slice granularity s=1;
[0040] Calculate the s of each slice size according to the slice order of month, week, day, and hour, and get s 月 、s 周 、s 天 、s 小时 ;
[0041] When 月 、s 周 、s 天 、s 小时 When the results of are all 0, s3=0; when s 月 、s 周 、s 天 、s 小时 When there is 1 in the result of , s3=0.25; when s 月 、s 周 、s 天 、s 小时 When there are 2 1s in the result, s3=0.5; when s 月 、s 周 、s 天 、s 小时 When there are 3 1s in the result, s3=0.75; when s 月 、s 周 、s 天 、s 小时 When there are 4 1s in the result, s3=1; where s3 is the third abnormality detection result.
[0042] Further, the step of calculating a final abnormality detection result of the power terminal according to the first abnormality detection result, the second abnormality detection result and the third abnormality detection result, and determining the possibility that the power terminal has an abnormality according to the final abnormality detection result includes:
[0043] Determine coefficients of a first abnormality detection result, a second abnormality detection result, and a third abnormality detection result; wherein the second abnormality detection result is s2;
[0044] Calculate the final abnormality detection result S of the power terminal; the calculation formula is:
[0045]
[0046] Among them, p i are coefficients of the first anomaly detection result, the second anomaly detection result, and the third anomaly detection result;
[0047] When S≥0.8, it is highly likely that the power terminal has an abnormality; when 0.8>S>0.5, it is highly likely that the power terminal has an abnormality; when 0.5≥S≥0.3, it is less likely that the power terminal has an abnormality; when S≤0.3, it is almost impossible that the power terminal has an abnormality.
[0048] The present invention also provides a power terminal anomaly detection system based on flow baseline, comprising:
[0049] A collection module, used to collect all network flow data of the power terminal, and identify and analyze the network flow data according to the protocol; wherein the protocol is a customized data specification used when the network flow data is transmitted between the power terminal and the upper platform;
[0050] A storage module is used to store all the power terminal network traffic sessions obtained after parsing in a big data platform and a structured database;
[0051] A first anomaly detection module is used to perform anomaly detection on the flow dimension of the power terminal according to the upper and lower limit statistics of the power terminal IP flow of the time slice, and obtain a first anomaly detection result;
[0052] A second anomaly detection module is used to perform anomaly detection on the protocol dimension of the power terminal according to the upper and lower limit statistics of the power terminal protocol flow of the time slice to obtain a second anomaly detection result;
[0053] A third anomaly detection module is used to perform anomaly detection on the application layer function code dimension of the power terminal according to the traffic size statistics of the application layer function code of the power terminal in the time slice, and obtain a third anomaly detection result;
[0054] The final abnormality calculation module is used to calculate the final abnormality detection result of the power terminal according to the first abnormality detection result, the second abnormality detection result and the third abnormality detection result, and determine the possibility of abnormality of the power terminal according to the final abnormality detection result.
[0055] The present invention also provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.
[0056] The present invention also provides a computer-readable storage medium on which a computer program is stored, and the computer program implements the steps of the above method when executed by a processor.
[0057] The beneficial effects of the present invention are:
[0058] The present invention performs layer-by-layer security detection on the network traffic data of power terminal assets from coarse to fine through three-dimensional traffic baselines, and performs security detection on the network traffic data generated by power terminal assets from multiple dimensions, thereby ensuring the comprehensiveness and accuracy of the terminal traffic detection dimension. At the same time, through the combined analysis of the three detection dimensions, the accuracy of power terminal asset anomaly detection based on the traffic baseline is further guaranteed.
[0059] The multi-dimensional detection method based on flow baseline of the present invention performs calculations on the basis of the unique network protocol transmission data of the power terminal, which can greatly improve the comprehensiveness and accuracy of flow anomaly detection of power terminal assets, and provide security guarantees for users to control whether the power terminal is operating normally and whether data delivery is carried out as a whole. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 Schematic diagram of method steps according to an embodiment of the present invention.
[0061] Figure 2 The figure is a schematic diagram of a method flow according to an embodiment of the present invention.
[0062] Figure 3 It is a schematic diagram of data parsing of data stream in the present invention.
[0063] Figure 4 This is an example diagram of a session record of traffic in the present invention.
[0064] Figure 5 FIG. 1 is a schematic diagram of a device structure according to an embodiment of the present invention.
[0065] Figure 6 The figure is a schematic diagram of the internal structure of a computer device according to an embodiment of the present invention.
[0066] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0067] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0068] like Figure 1 , 2 As shown, the present invention provides a method for detecting abnormalities in a power terminal based on a flow baseline, comprising:
[0069] S1. Collect all network flow data of the power terminal, and identify and parse the network flow data according to the protocol; wherein the protocol is a customized data specification used for network flow data transmission between the power terminal and the upper platform;
[0070] Step S1 specifically includes:
[0071] S11, receiving the power terminal network traffic mirrored to the network card by the aggregation and distribution device or switch;
[0072] S12, collecting data on the network card into the memory, and performing data recognition on the data collected into the memory according to the protocol;
[0073] S13, filtering, segmenting, combining, and deduplicating all the bitstream data stored in the memory according to the IP quintuple information;
[0074] S14. Parse the sorted traffic session data according to the transport layer protocol, frame data format, and application layer data format specified in the specification to obtain a session record of the network traffic.
[0075] As described in the above steps S11-S14, the network traffic of the power terminal is mirrored to the network card of the corresponding device of the system through the convergence and diversion equipment or switch. The system collects the data on the network card into the memory through various collection technologies, and performs data identification on the data collected in the memory according to various protocol requirements. Then, all the code stream data stored in the memory are filtered, fragmented, combined, and deduplicated according to the IP five-tuple information, and the sorted traffic session data is parsed according to the transport layer protocol, frame data format, and application layer data format specified in the protocol, and the parsing results are stored in the big data platform and structured database in the form of session records.
[0076] The protocol data analysis data includes:
[0077] 1. Transport layer protocol: Data transmission uses the TCP three-way handshake protocol for data transmission.
[0078] 2. Frame data format
[0079]
[0080]
[0081] 3. Application layer data format:
[0082]
[0083] The above analysis method can be used to analyze the data stream. Figure 3 shown.
[0084] After the analysis is completed, the session record of each flow is obtained as follows: Figure 4 shown.
[0085] S2, storing all the power terminal network traffic sessions obtained after parsing in the big data platform and structured database;
[0086] Step S2 specifically includes:
[0087] S21. Temporarily store all received power terminal network traffic sessions in the Kafka message middleware, and generate and consume data through the producer and consumer mode;
[0088] S22. Perform big data platform storage and structured data storage according to the data format and data volume that need to be stored.
[0089] As described in the above step S2, the data storage module includes a Kafka message middleware, a big data storage platform, and a structured database. The Kafka message middleware is mainly responsible for temporarily storing all received power terminal network traffic sessions, generating and consuming data through producer and consumer modes, and then performing big data platform storage and structured data storage according to the data format and data volume that need to be stored.
[0090] The power terminal traffic baseline analysis and detection algorithm includes three analysis and statistical algorithms: a power terminal IP traffic upper and lower limit statistical anomaly detection algorithm based on time slicing, a power terminal protocol traffic upper and lower limit statistical anomaly detection algorithm based on time slicing, and a power terminal application layer function code traffic size statistical anomaly detection algorithm based on time slicing. The three analysis and statistical algorithms are used to determine the abnormal conditions of the three dimensions of the power terminal's traffic, protocol, and application layer function code, which are steps S3, S4, and S5 respectively.
[0091] S3, performing anomaly detection on the traffic dimension of the power terminal according to the upper and lower limit statistics of the power terminal IP traffic of the time slice, and obtaining a first anomaly detection result;
[0092] Step S3 specifically includes:
[0093] S31, select a reference duration and a time slice granularity set; wherein the reference duration is greater than or equal to 2 days, and the power terminal flow data within the reference duration is normal data, and the time slice granularity set includes multiple time slices, namely: 1 minute time slice, 5 minute time slice, 10 minute time slice, 30 minute time slice and 60 minute time slice;
[0094] S32, the data at the same time point of each time slice in the reference duration is a data set D = {max, min, med, n}; wherein max represents the maximum value of the same time point on the time slice, min represents the minimum value of the same time point on the time slice, med represents the middle value of all the same time points on the slice, and n represents the number of accumulated data;
[0095] S33. The set of normal data of the power terminal IP at a time point in the past is D = {max, min, med, n}. The data at the time point obtained according to the slice granularity is d1, and d1 is equal to the sum of all session record traffic in the slice;
[0096] S34, calculating and obtaining a first abnormality detection result s1 according to d1; specifically comprising:
[0097] S341. When max=min=med, When s1=0, n=n+1; when s1>0, the user's instruction to determine whether d1 is added to the D data set is received; wherein s1 is the first abnormality detection result;
[0098] S342, when d1>max, When s1>1, s1=1;
[0099] S343, when d1<min, When s1>1, s1=1;
[0100] S344, when med≤d1≤max, Among them, med and n in D are recalculated, and the calculation of med is: when n is an even number, When n is an odd number, The calculation of n is: n=n+1;
[0101] S345, when min≤d1≤med, Among them, med and n in D are recalculated, and the calculation of med is: when n is an even number, When n is an odd number, The calculation of n is: n=n+1;
[0102] S346. When 0.8<s1≤1, the receiving user determines whether the traffic terminal point is added to D. If it is added to D, the max or min in D is modified, and the med and n values are modified in the same manner as when med≤d1≤max or min≤d1≤med.
[0103] As described in the above steps S31-S34, anomaly detection is performed on the flow dimension of the power terminal according to the upper and lower limit statistics of the power terminal IP flow in the time slice to obtain the first anomaly detection result s1. The statistical method selects a reference time length. In the reference time length, the maximum value, minimum value, and middle value of the power terminal of a certain IP at each time point in the time slice granularity are counted through the time dimension. A set of three numbers will be generated at each time point, and n data sets will be counted within the reference time length. The maximum value, minimum value, and middle value of the n data sets are taken to draw lines, and three curves can be drawn. The curve interval of the maximum value and the minimum value is the boundary baseline interval of normal flow. The probability of data outside this interval being abnormal data is more than 80%, and the probability of data being abnormal data within this interval is smaller, and the closer the data is to the middle value curve, the smaller the probability of abnormal data. Specifically:
[0104] 1) The time slice granularity can be the set T = {1, 5, 10, 30, 60}; which respectively represent 1 minute time slice, 5 minute time slice, 10 minute time slice, 30 minute time slice, and 60 minute time slice; the smaller the time slice, the more accurate the calculation, but the larger the data volume; the larger the slice, the rougher the calculation, but the smaller the data volume.
[0105] 2) Select a traffic benchmark time BT. Normally, the selection range of BT should be: BT ≥ 2 days, that is, the BT benchmark time should be greater than 2 days, and the BT benchmark time is not necessarily n consecutive days, but it must be ensured that the power terminal traffic data within the selected benchmark time is normal data, and the longer the BT benchmark time, the higher the accuracy. After the benchmark time data set D is determined, it will be continuously accumulated according to the time series.
[0106] 3) The data at the same time point in each time slice is a data set D = {max, min, med, n}; max represents the maximum value of the same time point on the time slice, min represents the minimum value of the same time point on the time slice, med represents the median value of all the same time points on the slice, and n represents the number of accumulated data; taking 10 as the benchmark time length and the slice granularity of 60 as an example, take the data set D at 12 noon, the traffic data between 11 o'clock and 12 o'clock in the benchmark time length of 10 days are respectively = {d1, d2, d3, d4, d5, d6, d7, d8, d9, d10}, max = max(d1, d2, d3, d4, d5, d6, d7, d8, d9, d10), min = min(d1, d2, d3, d4, d5, d6, d7, d8, d9, d10), med can directly calculate the median value during the benchmark calculation, and n = 10.
[0107] 4) Real-time data anomaly detection: the set of normal data of the power terminal IP at this time point every day in the past is D = {max, min, med, n}. At this time, the data at this time point is obtained according to the slice granularity as d1, d1 = the sum of all session record traffic in the slice. The detection based on whether d1 is abnormal includes:
[0108] a. When max=min=med, When s1=0, n=n+1; when s1>0, it is necessary to manually determine whether d1 should be added to the D data set.
[0109] b. When d1>max, When s1>1, s1=1;
[0110] c. When d1<min, When s1>1, s1=1;
[0111] d. When med≤d1≤max, At this time, it is necessary to recalculate med and n in D. The calculation of med is: when n is an even number, When n is an odd number, The calculation of n is: n=n+1;
[0112] e. When min≤d1≤med, At this time, it is necessary to recalculate med and n in D. The calculation of med is: when n is an even number, When n is an odd number, The calculation of n is: n=n+1;
[0113] f. When 0.8<s1≤1, it is necessary to manually determine whether the flow terminal point is suitable for addition to D. If not, it will not be added. If it is suitable, first modify the max or min in D, and then modify the med and n values according to the method of d or e.
[0114] S4. Perform anomaly detection on the protocol dimension of the power terminal according to the upper and lower limit statistics of the power terminal protocol flow of the time slice to obtain a second anomaly detection result.
[0115] As described in the above step S4, the algorithmic idea of the upper and lower limits statistical anomaly detection algorithm of the power terminal protocol protocol flow based on time slicing is similar to that of the upper and lower limits statistical anomaly detection algorithm of the power terminal IP flow based on time slicing. The difference is that the upper limit statistical anomaly detection based on the power terminal protocol protocol flow is based on the statistics and anomaly detection of the flow size of a certain protocol of multiple power terminals using the same flow transmission protocol. It can detect the abnormal situation of the flow of a certain protocol at a certain time point on a certain time slice granularity, which may include the flow of multiple power terminals. Therefore, when it is used in combination with the upper and lower limits statistical anomaly detection algorithm of the power terminal IP flow based on time slicing, the accuracy of anomaly detection is higher. The specific algorithmic idea of this algorithm refers to the specific algorithmic idea of the upper and lower limits statistical anomaly detection algorithm of the power terminal IP flow based on time slicing, which will not be repeated here.
[0116] S5, performing anomaly detection on the application layer function code dimension of the power terminal according to the traffic size statistics of the application layer function code of the power terminal in the time slice, and obtaining a third anomaly detection result;
[0117] Step S5 specifically includes:
[0118] S51, select a reference duration and a time slice granularity set; wherein the reference duration is greater than or equal to 1 hour, and the flow size of each time of the power terminal application layer function code within the reference duration is normal data, and the time slice granularity set includes multiple time slice methods, namely: time slice by 1 hour, time slice by 1 day, time slice by 1 week, and time slice by 1 month;
[0119] S52. In the reference duration, the data in each slice time is a two-dimensional data set D = {D1, D2, D3, ...}, Dn = {starttime, endtime, fcode, n, avg}; wherein starttime represents the start statistical time of the slice, endtime represents the end statistical time of the slice, fcode represents the application layer function code number, n represents the number of times the application layer function code is generated in the slice time, and avg represents the average flow of each access of the application layer function code in the slice time;
[0120] S53, calculate the specific value in the data set of each function code every day according to the time slice method in the time slice granularity set; wherein the data set of each function code every day is Dn={starttime, endtime, fcode, n, avg}, and the calculation formula of avg is: avg i Indicates the average traffic volume of each access of the same application layer function code every hour from 0 to 24 hours, n i Indicates the number of accesses to the same application layer function code every hour from 0 to 24 hours;
[0121] S54, obtaining the flow data size d2 accessed by the application layer function code of the power terminal, searching for the data set Dn corresponding to the application layer function code in the slice order of month, week, day, and hour, and comparing the flow size d2 with the avg in the same application layer function code Dn with the largest slice granularity;
[0122] S55, if Then the slice size s=0; if or Then the slice granularity s=1;
[0123] S56. Calculate s for each slice size according to the slice size of month, week, day, and hour, and obtain s 月 、s 周 、s 天 、s 小时 ;
[0124] S57, when s 月 、s 周 、s 天 、s 小时 When the results of are all 0, s3=0; when s 月 、s 周 、s 天 、s 小时 When there is 1 in the result of , s3=0.25; when s 月 、s 周 、s 天 、s 小时 When there are 2 1s in the result, s3=0.5; when s 月 、s 周 、s 天 、s 小时 When there are 3 1s in the result, s3=0.75; when s 月 、s 周 、s 天 、s 小时 When there are 4 1s in the result, s3=1; where s3 is the third abnormality detection result.
[0125] As described in the above steps S51-S57, the power terminal application layer function code flow size statistics anomaly detection algorithm based on time slicing first needs to select a time slicing period, and count the flow size of each application layer function code in each session within the time slicing period, and detect the abnormal situation of the power terminal by the flow size of the same application layer function code. Specifically, it includes:
[0126] 1) The time slice granularity is a data set T = {1, 24, 7×24, 30×24}, where 1 means time slice by 1 hour, 24 means time slice by 1 day, 7×24 means time slice by 1 week, and 30×24 means time slice by 1 month.
[0127] 2) Select a traffic benchmark duration BT. Normally, the selection range of BT should be: BT ≥ 1 hour, that is, the benchmark duration of BT should be greater than 1 hour, and ensure that the traffic size of the power terminal application layer function code within the benchmark duration is normal data each time. After the benchmark duration data set D is determined, it will continue to accumulate in time sequence.
[0128] 3) The data within each slice time is a two-dimensional data set D = {D1, D2, D3, ...}, Dn = {starttime, endtime, fcode, n, avg}, starttime represents the start statistical time of the slice, endtime represents the end statistical time of the slice, fcode represents the application layer function code number, such as: 00H for confirmation / denial, 01H for reset, 02H for link interface detection, 03H for relay station command, 04H for setting parameters, 05H for control command, ... 11H ~ FFH for spare, there are currently 16 main application layer function codes; n represents the number of times the application layer function code is generated in the slice time, avg represents the average traffic of each access of the application layer function code in the slice time.
[0129] 4) The 1-hour slice is the minimum slice granularity. The 1-day data set D is obtained by calculating the data set with the same function code in all data sets sliced by hour from 0:00 to 24:00 on the day. Then the data set of each function code per day Dn = {starttime, endtime, fcode, n, avg}, starttime = xx-xx-xx 0:0:0, endtime = xx-xx-xx23:59:59, fcode = fcode of the same application layer function code in the hourly slice, avg i Indicates the average traffic volume of each access of the same application layer function code every hour from 0 to 24 hours, n iIndicates the number of accesses to the same application layer function code every hour from 0 to 24 hours. Similarly, the 1-week data set is calculated based on the data of the 7 days of this week, and the 1-month data set is calculated based on the data of the 30 days of this month.
[0130] 5) Real-time data anomaly detection: obtain the flow data size d2 of a certain application layer function code of the power terminal, find the data set Dn corresponding to the application layer function code in the slice order of month, week, day, and hour, and compare the current flow size d2 with the avg in the same application layer function code Dn with the largest slice granularity. If It means that the traffic size of d2 is basically the same as that of most single visits of this slice granularity. Then s=0 for this slice granularity. or It means that the deviation between d2 and the traffic size of most single visits of this slice granularity is too large, then s=1 for this slice dimension; then find a slice with one granularity smaller than the current granularity, and use the above algorithm to make judgments until the smallest slice reaches the hour. When the hour slice dimension detection is completed, the anomaly detection is completed.
[0131] The default value of s for all slice granularities is s=0, s=0 indicates that the detection of this slice granularity is basically normal, s=1 indicates that the detection of this slice granularity may be abnormal. The final traffic detection result judgment includes: a. When the four s (month, week, day, hour) are all 0, s3=0; b. When there is 1 of the four s, s3=0.25; c. When there are 2 of the four s, s3=0.5; d. When there are 3 of the four s, s3=0.75; e. When there are 4 of the four s, s3=1.
[0132] S6. Calculate a final abnormality detection result of the power terminal according to the first abnormality detection result, the second abnormality detection result and the third abnormality detection result, and determine the possibility that the power terminal has an abnormality according to the final abnormality detection result.
[0133] S61, determining coefficients of the first abnormality detection result, the second abnormality detection result and the third abnormality detection result; wherein the second abnormality detection result is s2;
[0134] S62, calculating the final abnormality detection result S of the power terminal; wherein the calculation formula is:
[0135]
[0136] Among them, p i are coefficients of the first anomaly detection result, the second anomaly detection result, and the third anomaly detection result;
[0137] S63. When S≥0.8, it is highly likely that the power terminal has an abnormality; when 0.8>S>0.5, it is somewhat likely that the power terminal has an abnormality; when 0.5≥S≥0.3, it is less likely that the power terminal has an abnormality; when S≤0.3, it is almost impossible that the power terminal has an abnormality.
[0138] As described in the above steps S61-S63, based on the three abnormal detection results in the power terminal flow baseline analysis detection algorithm, the three detection results s1, s2, and s3 are calculated by formula to calculate whether the power terminal is abnormal. Since the three detection dimensions are different, their influence coefficients on whether the power terminal is abnormal are also different. The three detections are arranged according to the size of the influence as follows: Power terminal application layer function code flow size statistical anomaly detection algorithm based on time slicing ≥ Power terminal IP flow upper and lower limit statistical anomaly detection algorithm based on time slicing > Power terminal protocol protocol flow upper and lower limit statistical anomaly detection algorithm based on time slicing. Therefore, the coefficients corresponding to the three detection algorithms are as follows:
[0139] name coefficient Anomaly detection algorithm for traffic size statistics of function codes in power terminal application layer based on time slicing 0.4 Anomaly detection algorithm for upper and lower limit statistics of power terminal IP traffic based on time slicing 0.4 Anomaly detection algorithm for upper and lower limit statistics of power terminal protocol flow based on time slicing 0.2
[0140] Calculate the final anomaly detection results of the power terminal
[0141] According to the calculation of the final abnormality detection result S of the power terminal, the possibility of judging whether the power terminal has an abnormality is:
[0142] a. When S ≥ 0.8, there is a high possibility that the power terminal is abnormal;
[0143] b. When 0.8>S>0.5, there is a certain possibility of abnormality in the power terminal;
[0144] c. When 0.5 ≥ S > 0.3, the possibility of abnormality in the power terminal is small;
[0145] d. When S≤0.3, there is almost no possibility of abnormality in the power terminal.
[0146] The beneficial effects of the power terminal anomaly detection method based on flow baseline are:
[0147] Through the three-dimensional traffic baseline, the network traffic data of the power terminal assets is security checked layer by layer from coarse to fine, and the network traffic data generated by the power terminal assets is security checked from multiple dimensions, ensuring the comprehensiveness and accuracy of the terminal traffic detection dimension. At the same time, through the combined analysis of the three detection dimensions, the accuracy of the power terminal asset anomaly detection based on the traffic baseline is further guaranteed.
[0148] The multi-dimensional detection method based on traffic baseline is calculated on the basis of the unique network protocol transmission data of the power terminal. It can greatly improve the comprehensiveness and accuracy of traffic anomaly detection of power terminal assets, and provide security for users to control whether the power terminal is operating normally and whether data delivery is carried out as a whole.
[0149] like Figure 5 As shown, the present invention also provides a power terminal anomaly detection system based on flow baseline, comprising:
[0150] The collection module 1 is used to collect all network flow data of the power terminal, and identify and analyze the network flow data according to the protocol; wherein the protocol is a customized data specification used when the network flow data is transmitted between the power terminal and the upper platform;
[0151] Storage module 2, used to store all power terminal network traffic sessions obtained after parsing in a big data platform and a structured database;
[0152] A first anomaly detection module 3, configured to perform anomaly detection on the flow dimension of the power terminal according to the upper and lower limit statistics of the power terminal IP flow in the time slice, and obtain a first anomaly detection result;
[0153] A second anomaly detection module 4 is used to perform anomaly detection on the protocol dimension of the power terminal according to the upper and lower limit statistics of the power terminal protocol flow of the time slice to obtain a second anomaly detection result;
[0154] A third anomaly detection module 5 is used to perform anomaly detection on the application layer function code dimension of the power terminal according to the traffic size statistics of the application layer function code of the power terminal in the time slice, and obtain a third anomaly detection result;
[0155] The final abnormality calculation module 6 is used to calculate the final abnormality detection result of the power terminal according to the first abnormality detection result, the second abnormality detection result and the third abnormality detection result, and determine the possibility of the power terminal being abnormal according to the final abnormality detection result.
[0156] In one embodiment, the acquisition module 1 includes:
[0157] A mirroring unit, used to receive the power terminal network traffic mirrored to the network card by the aggregation and distribution equipment or the switch;
[0158] The flow collection unit is used to collect the data on the network card into the memory, and perform data identification on the data collected into the memory according to the protocol;
[0159] The code stream parsing unit is used to filter, segment, combine and remove duplicates of all code stream data stored in the memory according to the IP five-tuple information;
[0160] The specification identification unit is used to parse the sorted traffic session data according to the transport layer protocol, frame data format, and application layer data format specified in the specification to obtain the session record of the network traffic.
[0161] In one embodiment, the storage module 2 includes:
[0162] Kafka unit, used to temporarily store all received power terminal network traffic sessions in Kafka message middleware, and generate and consume data through producer and consumer mode;
[0163] The storage unit is used for big data platform storage or structured data storage according to the data format and data volume that need to be stored.
[0164] In one embodiment, the first anomaly detection module 3 includes:
[0165] A first selection unit is used to select a reference duration and a time slice granularity set; wherein the reference duration is greater than or equal to 2 days, and the power terminal flow data within the reference duration is normal data, and the time slice granularity set includes multiple time slices, namely: 1 minute time slice, 5 minute time slice, 10 minute time slice, 30 minute time slice and 60 minute time slice;
[0166] A first data set unit, for the data of the same time point of each time slice in the reference duration is a data set D = {max, min, med, n}; wherein max represents the maximum value of the same time point on the time slice, min represents the minimum value of the same time point on the time slice, med represents the middle value of all the same time points on the slice, and n represents the number of accumulated data;
[0167] The acquisition unit is used for the normal data set of the power terminal IP at a time point in the past every day, which is D = {max, min, med, n}. The data at the time point is obtained according to the slice granularity as d1, and d1 is equal to the sum of all session record traffic in the slice;
[0168] The first calculation unit is used to calculate and obtain a first abnormality detection result s1 according to d1.
[0169] In one embodiment, the first computing unit includes:
[0170] The first result subunit is used when max=min=med, When s1=0, n=n+1; when s1>0, the user's instruction to determine whether d1 is added to the D data set is received; wherein s1 is the first abnormality detection result;
[0171] The second result subunit is used when d1>max, When s1>1, s1=1;
[0172] The third result subunit is used when d1<min, When s1>1, s1=1;
[0173] The fourth result subunit is used when med≤d1≤max. Among them, med and n in D are recalculated, and the calculation of med is: when n is an even number, When n is an odd number, The calculation of n is: n=n+1;
[0174] The fifth result subunit is used when min≤d1≤med. Among them, med and n in D are recalculated, and the calculation of med is: when n is an even number, When n is an odd number, The calculation of n is: n=n+1;
[0175] The sixth result subunit is used to receive the user's determination whether the traffic terminal point is added to D when 0.8<s1≤1. If it is added to D, the max or min in D is modified, and the med and n values are modified in the same manner as when med≤d1≤max or min≤d1≤med.
[0176] In one embodiment, the third anomaly detection module 5 includes:
[0177] The second selection unit is used to select a reference duration and a time slice granularity set; wherein the reference duration is greater than or equal to 1 hour, and the flow size of each time of the power terminal application layer function code within the reference duration is normal data, and the time slice granularity set includes multiple time slice methods, namely: time slice by 1 hour, time slice by 1 day, time slice by 1 week, and time slice by 1 month;
[0178] The second data set unit is used for the data in each slice time in the reference time to be a two-dimensional data set D={D1, D2, D3, ...}, Dn={starttime, endtime, fcode, n, avg}; wherein starttime represents the start statistical time of the slice, endtime represents the end statistical time of the slice, fcode represents the application layer function code number, n represents the number of times the application layer function code is generated in the slice time, and avg represents the average flow of each access of the application layer function code in the slice time;
[0179] The second calculation unit is used to calculate the specific value of each function code in the data set of each day according to the time slice method in the time slice granularity set; wherein the data set of each function code of each day is Dn = {starttime, endtime, fcode, n, avg}, and the calculation formula of avg is: avg i Indicates the average traffic volume of each access of the same application layer function code every hour from 0 to 24 hours, n i Indicates the number of accesses to the same application layer function code every hour from 0 to 24 hours;
[0180] A comparison unit is used to obtain the flow data size d2 accessed by the application layer function code of the power terminal, find the data set Dn corresponding to the application layer function code from the slice order of month, week, day and hour, and compare the flow size d2 with the avg in the same application layer function code Dn with the largest slice granularity;
[0181] Comparison result unit, used when When , the slice size s=0; when or When , the slice granularity s=1;
[0182] The third calculation unit is used to calculate s of each slice size according to the slice sequence of month, week, day, and hour, and obtain s 月 、s 周 、s 天 、s 小时 ;
[0183] Test result unit, used when s 月 、s 周 、s 天 、s 小时 When the results of are all 0, s3=0; when s 月 、s 周 、s 天 、s 小时 When there is 1 in the result of , s3=0.25; when s 月 、s 周 、s 天 、s 小时 When there are 2 1s in the result, s3=0.5; when s 月 、s 周 、s 天 、s 小时 When there are 3 1s in the result, s3=0.75; when s 月 、s 周 、s 天 、s 小时When there are 4 1s in the result, s3=1; where s3 is the third abnormality detection result.
[0184] In one embodiment, the final abnormality calculation module 6 includes:
[0185] A coefficient determination unit, used to determine coefficients of a first abnormality detection result, a second abnormality detection result, and a third abnormality detection result; wherein the second abnormality detection result is s2;
[0186] The abnormality detection result calculation unit is used to calculate the final abnormality detection result S of the power terminal; wherein the calculation formula is:
[0187]
[0188] Among them, p i are coefficients of the first anomaly detection result, the second anomaly detection result, and the third anomaly detection result;
[0189] The abnormality possibility judgment unit is used to display that when S≥0.8, the possibility of abnormality in the power terminal is relatively high; when 0.8>S>0.5, the possibility of abnormality in the power terminal is relatively low when 0.5≥S≥0.3; when S≤0.3, the possibility of abnormality in the power terminal is almost non-existent.
[0190] The above modules, units and sub-units are used to execute the corresponding steps in the above-mentioned power terminal abnormality detection method based on flow baseline. The specific implementation method thereof is described in the above-mentioned method embodiment and will not be repeated here.
[0191] like Figure 6 As shown, the present invention also provides a computer device, which can be a server, and its internal structure can be as shown in Figure 6 As shown. The computer device includes a processor, a memory, a network interface and a database connected through a system bus. Among them, the processor designed by the computer is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store all data required for the process of the power terminal anomaly detection method based on the flow baseline. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the power terminal anomaly detection method based on the flow baseline is implemented.
[0192] Those skilled in the art will understand that Figure 6The structure shown in is merely a block diagram of a portion of the structure related to the present application solution and does not constitute a limitation on the computer device to which the present application solution is applied.
[0193] An embodiment of the present application also provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, any one of the above-mentioned methods for detecting abnormalities in power terminals based on a flow baseline is implemented.
[0194] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing related hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media provided in this application and used in the embodiments may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0195] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, device, article or method including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, device, article or method. In the absence of further restrictions, an element defined by the sentence "includes a ..." does not exclude the presence of other identical elements in the process, device, article or method including the element.
[0196] The above description is only a preferred embodiment of the present invention, and does not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A method for detecting abnormality of a power terminal based on a flow baseline, characterized in that: include: Collect all network traffic data of the power terminal, and identify and parse the network traffic data according to the protocol; wherein the protocol is a customized data specification used when the network traffic data is transmitted between the power terminal and the upper platform; All the power terminal network traffic sessions obtained after parsing are stored in the big data platform and structured database; Anomaly detection is performed on the traffic dimension of the power terminal according to the upper and lower limit statistics of the power terminal IP traffic of the time slice to obtain a first anomaly detection result; Anomaly detection is performed on the protocol dimension of the power terminal according to the upper and lower limit statistics of the power terminal protocol flow of the time slice to obtain a second anomaly detection result; Perform anomaly detection on the application layer function code dimension of the power terminal according to the traffic size statistics of the application layer function code of the power terminal in the time slice, and obtain a third anomaly detection result; A final abnormality detection result of the power terminal is calculated according to the first abnormality detection result, the second abnormality detection result and the third abnormality detection result, and a possibility that the power terminal has an abnormality is determined according to the final abnormality detection result.
2. The power terminal anomaly detection method based on flow baseline according to claim 1 is characterized in that: The step of collecting all network flow data of the power terminal, identifying and parsing the network flow data according to the protocol, and obtaining the network flow session includes: Receive power terminal network traffic mirrored to the network card by aggregation and distribution equipment or switches; Collect the data on the network card into the memory, and perform data recognition on the data collected in the memory according to the protocol; All the bitstream data stored in the memory is filtered, segmented, combined, and deduplicated according to the IP quintuple information; The sorted traffic session data is parsed according to the transport layer protocol, frame data format, and application layer data format specified in the specification to obtain the session record of the network traffic.
3. The power terminal anomaly detection method based on flow baseline according to claim 1 is characterized in that: The step of storing all the power terminal network flow sessions obtained after parsing in the big data platform and the structured database includes: Temporarily store all received power terminal network traffic sessions in the Kafka message middleware, and generate and consume data through the producer and consumer mode; Big data platform storage and structured data storage are performed according to the data format and data volume that need to be stored.
4. The power terminal anomaly detection method based on flow baseline according to claim 1 is characterized in that: The step of performing anomaly detection on the flow dimension of the power terminal according to the upper and lower limit statistics of the power terminal IP flow of the time slice to obtain a first anomaly detection result includes: A reference duration and a time slice granularity set are selected; wherein the reference duration is greater than or equal to 2 days, and the power terminal flow data within the reference duration is normal data, and the time slice granularity set includes multiple time slices, namely: 1 minute time slice, 5 minute time slice, 10 minute time slice, 30 minute time slice and 60 minute time slice; The data at the same time point of each time slice in the reference duration is a data set D = {max, min, med, n}; wherein max represents the maximum value at the same time point on the time slice, min represents the minimum value at the same time point on the time slice, med represents the middle value of all the same time points on the slice, and n represents the number of accumulated data; The set of normal data of the power terminal IP at a time point in the past is D = {max, min, med, n}. The data at the time point obtained according to the slice granularity is d1, and d1 is equal to the sum of all session record traffic in the slice; The first abnormality detection result s1 is calculated based on d1.
5. The power terminal anomaly detection method based on flow baseline according to claim 4 is characterized in that: The step of calculating the first abnormality detection result s1 according to d1 includes: When max=min=med, When s1=0, n=n+1; when s1>0, the user's instruction to determine whether d1 is added to the D data set is received; wherein s1 is the first abnormality detection result; When d1>max, When s1>1, s1=1; When d1<min, When s1>1, s1=1; When med≤d1≤max, Among them, med and n in D are recalculated, and the calculation of med is: when n is an even number, When n is an odd number, The calculation of n is: n=n+1; When min≤d1≤med, Among them, med and n in D are recalculated, and the calculation of med is: when n is an even number, When n is an odd number, The calculation of n is: n=n+1; When 0.8<s1≤1, the receiving user determines whether the traffic terminal point is added to D. If it is added to D, the max or min in D is modified, and the med and n values are modified in the same manner as when med≤d1≤max or min≤d1≤med.
6. The power terminal anomaly detection method based on flow baseline according to claim 1 is characterized in that: The step of performing anomaly detection on the application layer function code dimension of the power terminal according to the traffic size statistics of the application layer function code of the power terminal of the time slice to obtain the third anomaly detection result includes: A reference duration and a time slice granularity set are selected; wherein the reference duration is greater than or equal to 1 hour, and the flow size of each time of the power terminal application layer function code within the reference duration is normal data, and the time slice granularity set includes multiple time slice methods, namely: time slice by 1 hour, time slice by 1 day, time slice by 1 week, and time slice by 1 month; In the benchmark duration, the data in each slice time is a two-dimensional data set D = {D1, D2, D3, ...}, Dn = {starttime, endtime, fcode, n, avg}; where starttime represents the start statistical time of the slice, endtime represents the end statistical time of the slice, fcode represents the application layer function code number, n represents the number of times the application layer function code is generated in the slice time, and avg represents the average traffic of each access of the application layer function code in the slice time; The specific value in the data set of each function code per day is calculated according to the time slice method in the time slice granularity set; wherein the data set of each function code per day is Dn={starttime, endtime, fcode, n, avg}, and the calculation formula of avg is: avg i Indicates the average traffic volume of each access of the same application layer function code every hour from 0 to 24 hours, n i Indicates the number of accesses to the same application layer function code every hour from 0 to 24 hours; Obtain the flow data size d2 accessed by the application layer function code of the power terminal, find the data set Dn corresponding to the application layer function code from the slice order of month, week, day, and hour, and compare the flow size d2 with the avg in the same application layer function code Dn with the largest slice granularity; like Then the slice size s=0; if or Then the slice granularity s=1; Calculate the s of each slice size according to the slice order of month, week, day, and hour, and get s 月 、s 周 、s 天 、s 小时 ; When 月 、s 周 、s 天 、s 小时 When the results of are all 0, s3=0; when s 月 、s 周 、s 天 、s 小时 When there is 1 in the result of , s3=0.25; when s 月 、s 周 、s 天 、s 小时 When there are 2 1s in the result, s3=0.5; when s 月 、s 周 、s 天 、s 小时 When there are 3 1s in the result, s3=0.75; when s 月 、s 周 、s 天 、s 小时 When there are 4 1s in the result, s3=1; where s3 is the third abnormality detection result.
7. The power terminal anomaly detection method based on flow baseline according to claim 1 is characterized in that: The step of calculating a final abnormality detection result of the power terminal according to the first abnormality detection result, the second abnormality detection result and the third abnormality detection result, and determining the possibility that the power terminal has an abnormality according to the final abnormality detection result, comprises: Determine coefficients of a first abnormality detection result, a second abnormality detection result, and a third abnormality detection result; wherein the second abnormality detection result is s2; Calculate the final abnormality detection result S of the power terminal; the calculation formula is: Among them, p i are coefficients of the first anomaly detection result, the second anomaly detection result, and the third anomaly detection result; When S≥0.8, it is highly likely that the power terminal has an abnormality; when 0.8>S>0.5, it is highly likely that the power terminal has an abnormality; when 0.5≥S≥0.3, it is less likely that the power terminal has an abnormality; when S≤0.3, it is almost impossible that the power terminal has an abnormality.
8. A power terminal anomaly detection system based on flow baseline, characterized in that: include: A collection module, used to collect all network flow data of the power terminal, and identify and analyze the network flow data according to the protocol; wherein the protocol is a customized data specification used when the network flow data is transmitted between the power terminal and the upper platform; A storage module is used to store all the power terminal network traffic sessions obtained after parsing in a big data platform and a structured database; A first anomaly detection module is used to perform anomaly detection on the flow dimension of the power terminal according to the upper and lower limit statistics of the power terminal IP flow of the time slice, and obtain a first anomaly detection result; A second anomaly detection module is used to perform anomaly detection on the protocol dimension of the power terminal according to the upper and lower limit statistics of the power terminal protocol flow of the time slice to obtain a second anomaly detection result; A third anomaly detection module is used to perform anomaly detection on the application layer function code dimension of the power terminal according to the traffic size statistics of the application layer function code of the power terminal in the time slice, and obtain a third anomaly detection result; The final abnormality calculation module is used to calculate the final abnormality detection result of the power terminal according to the first abnormality detection result, the second abnormality detection result and the third abnormality detection result, and determine the possibility of abnormality of the power terminal according to the final abnormality detection result.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Industrial control network anomaly detection method and device, electronic equipment and storage medium
CN114124658A
Abnormal behavior detection method and device, terminal equipment and storage medium
CN114301645A