Intrusion Detection and Defense Method, Device, Equipment and Medium Based on Intranet Traffic
By analyzing the intranet traffic characteristic information and adjusting the risk judgment rules during the learning cycle, the problems of high intrusion and insufficient accuracy of the equipment are solved, and efficient intrusion detection and defense are achieved.
Patent Information
- Application Number
- CN202211143193.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-20
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2042-09-20
AI Technical Summary
The existing intrusion detection methods based on intranet traffic are highly invasive and have insufficient accuracy, so they cannot effectively judge and defend against network intrusion.
By obtaining the host's traffic message file, analyzing feature information, setting preset risk judgment rules, and adjusting the rules during the learning cycle to obtain target risk judgment rules, judging the risk level based on feature information and performing corresponding disposal.
Reduces equipment intrusion, improves the accuracy and accuracy of intrusion detection and defense, and can prevent intrusion spread at the network level.
Smart Images

Figure CN115514556B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer technology, and particularly relates to an intrusion detection and prevention method, device, equipment and medium based on intranet traffic. Background Art
[0002] At present, with the rapid development of the Internet, network security has become a hot topic, and various means have been used in the game of attack and defense. As a means of post-attack defense, intrusion detection and prevention make up for the deficiencies of pre-attack defense products such as firewalls and WAFs (Web Application Firewalls), and provide various methods for process monitoring, resource usage, etc. to timely alarm intrusion events. However, the existing methods that rely on Agents to monitor indicators such as process status and resource usage for intrusion detection have a relatively high invasiveness to devices.
[0003] In the existing methods, some extract traffic fingerprint information, and then judge whether there is a compromise according to a preset malicious fingerprint library and the fingerprint information. It includes a traffic acquisition unit, a fingerprint extraction unit, a judgment unit, a determination unit, and a marking unit. The technical key point of this method lies in the fingerprint library, but the content details of the fingerprint library are not disclosed, and it can only determine which host is compromised.
[0004] In summary, how to reduce the invasiveness of devices in the process of intrusion detection and prevention and improve the accuracy is an urgent problem to be solved at present. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide an intrusion detection and prevention method, device, equipment and medium based on intranet traffic, which can reduce the invasiveness of devices in the process of intrusion detection and prevention and improve the accuracy. The specific solutions are as follows:
[0006] In the first aspect, the present application discloses an intrusion detection and prevention method based on intranet traffic, including:
[0007] Obtain a plurality of traffic packet files corresponding to a plurality of hosts, and parse the traffic packet files to obtain feature information in different dimensions;
[0008] Obtain a preset risk judgment rule and a risk handling rule set for the host, and adjust the preset risk judgment rule within a preset learning period until the target risk judgment rule is obtained at the end of the preset learning period;
[0009] Based on the target risk judgment rule, and according to the feature information, judge the target risk level corresponding to the corresponding host;
[0010] Based on the risk handling rules, determine the corresponding target handling method for the corresponding host according to the target risk level, and then handle the corresponding host based on the target handling method.
[0011] Optionally, adjusting the preset risk judgment rules within a preset learning period until the end of the preset learning period to obtain the target risk judgment rules includes:
[0012] Based on the preset risk judgment rules, judge the reference risk level of the host according to the feature information;
[0013] Construct reference alarm information based on the target information; the target information includes the host identifier representing the host, the reference risk level, and the reference rule in the preset risk judgment rules for judging the host as the reference risk level;
[0014] Obtain the judgment result of whether the alarm information is a false alarm from the client, adjust the reference rule according to the judgment result to obtain a new preset risk judgment rule, and then jump to the step based on the preset risk judgment rules until the end of the preset learning period to obtain the target risk judgment rules.
[0015] Optionally, the preset risk judgment rules include a number of reference rules; the reference rule is the risk corresponding to a preset condition when a target situation of a feature combination of different dimensions of the feature information corresponding to the same host is satisfied.
[0016] Optionally, adjusting the reference rule according to the judgment result to obtain a new preset risk judgment rule includes:
[0017] Determine the target proportion of false alarms in the judgment result;
[0018] If the target proportion is different from the preset proportion, adjust the preset threshold of the feature combination corresponding to the reference rule to obtain a new preset risk judgment rule.
[0019] Optionally, the feature information includes the source MAC, source IP, packet type, packet size, and packet time corresponding to the traffic packet file.
[0020] Optionally, the intrusion detection and prevention method based on the internal network traffic further includes:
[0021] Adjust the frequency of the step of obtaining a number of traffic packet files corresponding to a number of hosts according to the utilization rate of the target resources corresponding to the host.
[0022] Optionally, obtaining a number of traffic packet files corresponding to a number of hosts includes:
[0023] Obtain a number of traffic packet files corresponding to a number of hosts through a third - party interface provided by a target network device;
[0024] Correspondingly, determining a target handling method corresponding to the corresponding host according to the target risk level, and then handling the corresponding host based on the target handling method includes:
[0025] If the target risk level is high - risk, the target handling method is blocking processing, and the blocking processing of the host is executed in the target network device corresponding to the host to prevent the spread of the compromised situation at the network level;
[0026] If the target risk level is low - risk or medium - risk, the target handling method is warning processing. Construct a target warning message based on the host identifier representing the host, the target risk level, and the target rule in the target risk judgment rule for determining the host as the target risk level, and send it to the client.
[0027] In a second aspect, an intrusion detection and prevention device based on intranet traffic according to the present application includes:
[0028] A feature information acquisition module, configured to obtain a number of traffic packet files corresponding to a number of hosts, and parse the traffic packet files to obtain feature information in different dimensions;
[0029] A learning module, configured to obtain a preset risk judgment rule and a risk handling rule set for the host, and adjust the preset risk judgment rule within a preset learning period until the target risk judgment rule is obtained at the end of the preset learning period
[0030] A risk level judgment module, configured to judge the target risk level corresponding to the corresponding host based on the target risk judgment rule and according to the feature information;
[0031] A handling module, configured to determine a target handling method corresponding to the corresponding host based on the risk handling rule and according to the target risk level, and then handle the corresponding host based on the target handling method.
[0032] In a third aspect, the present application discloses an electronic device, including a processor and a memory; wherein, when the processor executes a computer program stored in the memory, the intrusion detection and prevention method based on intranet traffic disclosed above is implemented.
[0033] In a fourth aspect, the present application discloses a computer - readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the intrusion detection and prevention method based on intranet traffic disclosed above is implemented.
[0034] It can be seen that the present application obtains a number of traffic packet files corresponding to a number of hosts, and parses the traffic packet files to obtain feature information in different dimensions; obtains preset risk judgment rules and risk handling rules set for the hosts, and adjusts the preset risk judgment rules within a preset learning period until the end of the preset learning period to obtain target risk judgment rules; based on the target risk judgment rules, and according to the feature information, determines the target risk level corresponding to the corresponding host; based on the risk handling rules, and according to the target risk level, determines the target handling method corresponding to the corresponding host, and then disposes of the corresponding host based on the target handling method. Thus, it can be seen that the present application performs intrusion detection and prevention by obtaining traffic packet files, reducing the invasiveness of devices; by continuously adjusting the preset risk judgment rules through a preset learning period, the accuracy and precision of intrusion detection and prevention can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention, and for those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0036] Figure 1 It is a flowchart of an intrusion detection and prevention method based on intranet traffic provided by the present application;
[0037] Figure 2 It is a specific flowchart of an intrusion detection and prevention method based on intranet traffic provided by the present application;
[0038] Figure 3 It is a schematic diagram of an intrusion detection and prevention process based on intranet traffic taking a router as an example provided by the present application;
[0039] Figure 4 It is a schematic diagram of the structure of an intrusion detection and prevention device based on intranet traffic provided by the present application;
[0040] Figure 5 It is a structural diagram of an electronic device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0041] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0042] Currently, the Internet is developing rapidly, and network security has become a hot topic, with various players showing their skills in the game of offense and defense. As a post-attack defense means, intrusion detection and prevention make up for the deficiencies of pre-attack defense products such as firewalls and WAFs, providing various methods for process monitoring, resource usage, etc. to timely alert intrusion events. However, the existing methods that rely on agents to monitor indicators such as process status and resource usage for intrusion detection have a relatively high invasiveness to devices; in the existing methods, some extract traffic fingerprint information and then determine whether there is a compromise based on a preset malicious fingerprint library and the fingerprint information. It includes a traffic acquisition unit, a fingerprint extraction unit, a judgment unit, a determination unit, and a marking unit. The technical key point of this method lies in the fingerprint library, but the content details of the fingerprint library are not disclosed, and it can only determine which host is compromised.
[0043] To overcome the above problems, the present application provides an intrusion detection and prevention solution based on intranet traffic, which can reduce the invasiveness and improve the accuracy of devices during the process of intrusion detection and prevention.
[0044] See Figure 1 As shown, the embodiments of the present application disclose an intrusion detection and prevention method based on intranet traffic, and the method includes:
[0045] Step S11: Obtain a plurality of traffic packet files corresponding to a plurality of hosts, and parse the traffic packet files to obtain feature information in different dimensions.
[0046] In the embodiments of the present application, a plurality of traffic packet files are obtained through a third-party interface provided by a target network device. It should be noted that the target network device includes, but is not limited to, a router. The method of obtaining the plurality of traffic packet files (traffic packets) includes capturing and downloading. It should be noted that the step of parsing the traffic packet files to obtain feature information in different dimensions is completed by a feature extraction module. Specifically, according to the OSI (Open System Interconnection Reference Model) seven-layer model, each packet is parsed. It should be noted that the step of obtaining a plurality of traffic packet files corresponding to a plurality of hosts and sending the traffic packet files to the feature extraction module is completed by a traffic collection module.
[0047] It should be noted that the feature information includes the source MAC (Media Access Control, physical address), source IP (Internet Protocol), packet type, packet size, and packet time corresponding to the traffic packet file. It should be noted that the above-mentioned dimensions are IP, type, size, and time, etc.
[0048] In the embodiment of the present application, the frequency of the step of obtaining several traffic packet files is adjusted according to the utilization rate adjustment of the target resource corresponding to the host, that is, the frequency of the traffic collection module playing a role is adjusted. It should be noted that the step of adjusting the frequency is completed by the central scheduling module, and the target resources include but are not limited to the CPU (central processing unit) and memory; if the utilization rate is too high, the frequency of traffic collection is reduced.
[0049] It should be noted that when parsing the traffic packet files of multiple hosts at the same time, it is necessary to distinguish the feature information of different hosts.
[0050] Step S12: Obtain the preset risk judgment rule and risk handling rule set for the host, and adjust the preset risk judgment rule within a preset learning period until the target risk judgment rule is obtained at the end of the preset learning period.
[0051] In the embodiment of the present application, the preset risk judgment rule and risk handling rule set for the host can be pre-set or temporarily set by the client. It should be noted that risk judgment is the basic library for defense. Each host sets a risk level according to the extracted feature information, and different risk levels have different handling actions.
[0052] In the embodiment of the present application, adjusting the preset risk judgment rule to the target risk judgment rule within a preset learning period can improve the accuracy of judgment.
[0053] In the embodiment of the present application, the preset risk judgment rule classifies the risks into no risk, low risk, medium risk, and high risk; the risk handling rule stipulates that no treatment is done for no-risk breaches, warning treatment is done for low-risk and medium-risk breaches, and blocking treatment is done for high-risk breaches. ]>
[0054] Step S13: Based on the target risk judgment rule, and according to the feature information, judge the corresponding target risk level of the host.
[0055] Step S14: Based on the risk handling rule, and according to the target risk level, determine the corresponding target handling method for the host, and then perform handling on the corresponding host based on the target handling method.
[0056] In the embodiment of the present application, if the target risk level is high risk, the target handling method is blocking processing, and the blocking processing of the host is performed in the target network device corresponding to the host to prevent the spread of the compromised situation at the network level; if the target risk level is low risk or medium risk, the target handling method is warning processing, and a target warning message is constructed based on the host identifier representing the host, the target risk level, and the target rule in the target risk judgment rule for determining the host as the target risk level, and sent to the client.
[0057] In the embodiment of the present application, an intrusion detection and prevention method based on internal network traffic analysis is proposed, which considers post-event protection from a brand-new perspective. Compared with the existing intrusion detection that relies on an Agent to monitor indicators such as process status and resource usage, the present application has low invasiveness to devices and can set risk levels and perform different handling behaviors for compromised hosts with different risk levels. In summary, the present application can achieve intrusion detection by capturing and analyzing network traffic and achieve intrusion prevention by calling the third-party interface of the network device.
[0058] It can be seen that the present application obtains a plurality of traffic packet files corresponding to a plurality of hosts, and parses the traffic packet files to obtain feature information in different dimensions; obtains a preset risk judgment rule and a risk handling rule set for the host, and adjusts the preset risk judgment rule within a preset learning period until the end of the preset learning period to obtain a target risk judgment rule; based on the target risk judgment rule, and according to the feature information, determines the target risk level corresponding to the corresponding host; based on the risk handling rule, and according to the target risk level, determines the target handling method corresponding to the corresponding host, and then performs handling on the corresponding host based on the target handling method. Thus, the present application performs intrusion detection and prevention by obtaining traffic packet files, reducing the invasiveness of the device; by adjusting the preset risk judgment rule through a preset learning period to obtain a target risk judgment rule, it can improve the accuracy of intrusion detection and prevention.
[0059] See Figure 2 As shown, the embodiment of the present application discloses a specific intrusion detection and prevention method based on internal network traffic, and the method includes:
[0060] Step S21: Obtain a plurality of traffic packet files corresponding to a plurality of hosts, and parse the traffic packet files to obtain feature information in different dimensions.
[0061] In the embodiment of the present application, after obtaining the feature information in different dimensions, it is also necessary to aggregate the feature information; for example, count the number of requests initiated by each source IP. The aggregation process is completed by the risk judgment module.
[0062] Step S22: Obtain the preset risk judgment rule and risk handling rule set for the host, and then, based on the preset risk judgment rule, judge the reference risk level of the host according to the feature information.
[0063] In the embodiment of the present application, if the ratio of the total number of requests initiated by a certain source IP to the total number of times exceeds 50%, it is determined as a risky IP.
[0064] Step S23: Construct a reference alarm message based on the target information; the target information includes the host identifier representing the host, the reference risk level, and the reference rule in the preset risk judgment rule for determining the host as the reference risk level.
[0065] In the embodiment of the present application, the preset risk judgment rule includes several reference rules; the reference rule is the risk corresponding to the target situation that a feature combination of the feature information of different dimensions corresponding to the same host meets the preset conditions. It should be noted that the reference rules can be as follows: 1. For the same SMAC, within the TCP (Transmission Control Protocol) communication time span, if the proportion of packets with a length of 1500Length exceeds 80%, the host is determined to be high-risk; 2. For the same SMAC, within the TCP communication time span, if the proportion of packets with a length less than 80Length exceeds 75%, the host is determined to be high-risk; 3. For the same SMAC, if the number of TCP requests initiated within one minute exceeds 120 times, the host is determined to be medium-risk; 4. For the same SMAC, if the number of TCP requests initiated within one minute exceeds 500 times, the host is determined to be high-risk; 5. For the same SMAC, if the TCP requests initiated in the early morning account for more than 50% of the total requests, the host is determined to be high-risk. The above reference rules can generally constitute the preset risk judgment rule. It should be noted that the host identifier is used to distinguish different hosts and can correspond to the above SMAC or IP. It should be noted that for "for the same SMAC, within the TCP communication time span, if the proportion of packets with a length less than 80Length exceeds 75%, the host is determined to be high-risk", the present application is a feature combination of SMAC and packet size, the target situation is the proportion of packets with a length less than 80Length in all packets of all hosts under this feature combination, and the preset condition is that it exceeds the preset threshold (75%); for "for the same SMAC, if the number of TCP requests initiated within one minute exceeds 120 times, the host is determined to be medium-risk", the present application is a feature combination of SMAC and TCP requests, the target situation is the number of TCP requests initiated within one minute, and the preset condition is that it exceeds 120 times.
[0066] It should be noted that within the preset learning cycle, all handling actions are alarms, and the alarm information clearly indicates which host it is and which reference rule it matches.
[0067] Step S24: Obtain the client's judgment result on whether the alarm information is a false alarm, adjust the reference rule according to the judgment result to obtain the new preset risk judgment rule, and jump to the step based on the preset risk judgment rule within the preset learning cycle until the preset learning cycle ends to obtain the target risk judgment rule.
[0068] In the embodiment of the present application, after the preset risk judgment rules are constructed, the preset risk judgment rules need to be optimized to make them more accurate; therefore, a preset learning cycle is set, and within the preset learning cycle, pre-processing actions are displayed to the user. For example, when a high-risk compromised host information is received, according to the preset risk judgment rules and risk handling rules, the pre-processing method is blocking, and the handling action is pushed to the administrator. If it is a misjudgment, the credibility of the high-risk compromise in the basic handling rules is automatically reduced. After reaching a standard, the handling action is changed from interception to alarm, thereby achieving adaptation to the customer network environment and achieving better handling action matching for the actual environment through a learning cycle.
[0069] In the embodiment of the present application, the client needs to make a manual judgment on the accuracy of the alarm information based on the alarm information. If it is found that the host in the alarm information is clearly not likely to be lost, it is marked as a false alarm.
[0070] In an embodiment of the present application, the adjustment of the reference rule according to the judgment result to obtain the new preset risk judgment rule includes: determining the target proportion of the false alarm in the judgment result; if the target proportion is different from the preset proportion, adjusting the preset threshold of the feature combination corresponding to the reference rule to obtain the new preset risk judgment rule. It should be pointed out that if the target proportion reaches the preset proportion, the preset threshold set in the rule is proportionally lowered. For example, the proportion of messages reaching 1500 Length within the TCP communication time span in the rule is reduced from more than 80% to 78%. On the contrary, if the target proportion (the overall proportion of false alarms) does not reach the preset proportion (expected threshold), the value set in the rule is proportionally increased, for example, from 80% to 81%.
[0071] It should be pointed out that the learning process is completed jointly by the risk disposal module and the risk judgment module.
[0072] Step S25: Based on the target risk judgment rule and according to the characteristic information, the target risk level corresponding to the corresponding host is judged.
[0073] Among them, for a more specific processing procedure of step S25, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated herein.
[0074] Step S26: Based on the risk handling rule, determine the target handling method corresponding to the corresponding host according to the target risk level, and then handle the corresponding host based on the target handling method.
[0075] Among them, for a more specific processing procedure of step S26, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated herein.
[0076] It can be seen that this application obtains a plurality of traffic packet files corresponding to a plurality of hosts, parses the traffic packet files to obtain feature information in different dimensions; obtains a preset risk judgment rule and a risk handling rule set for the host, and then based on the preset risk judgment rule, judges the reference risk level of the host according to the feature information; constructs reference alarm information based on the target information; the target information includes the host identifier representing the host, the reference risk level, and the reference rule in the preset risk judgment rule for judging the host as the reference risk level; obtains the judgment result of the client on whether the alarm information is a false alarm, adjusts the reference rule according to the judgment result to obtain a new preset risk judgment rule, and jumps to the step based on the preset risk judgment rule within a preset learning period until the preset learning period ends to obtain a target risk judgment rule; based on the target risk judgment rule, judge the target risk level corresponding to the corresponding host according to the feature information; based on the risk handling rule, determine the target handling method corresponding to the corresponding host according to the target risk level, and then handle the corresponding host based on the target handling method. Thus, it can be seen that this application performs intrusion detection and prevention by obtaining traffic packet files, reducing the invasiveness of the device; by adjusting the preset risk judgment rule through a preset learning period to obtain a target risk judgment rule, the accuracy of intrusion detection and prevention can be improved.
[0077] See Figure 3As shown in the figure, it is a schematic diagram of the intrusion detection and prevention method process taking a router as an example; in the internal network, Router 1 is connected to Host 3, and Router 2 is connected to Host 1 and Host 2. Among them, Host 1 is compromised, and Host 2 and Host 3 are normal; the router product itself provides the function of capturing network packets according to filtering conditions such as network interfaces and forming pcap files for viewing. First, the traffic collection module: completes traffic collection by calling the router packet capture interface in the internal network and uploads the collected pcap packet file to the feature extraction module; the feature extraction module: performs hierarchical parsing on the packet file obtained from the traffic collection module, records the SMAC field in the Ethernet frame header, the Source IP field in the IP header, records the Protocol field in the IP layer header, records the Length field in the IP header, and the TimeStamp field in the TCP header. Aggregate the information of each field with SMAC as the key; the risk judgment module: risk judgment is the basic library of defense. Each host sets a risk level according to the extracted features, and different risk levels have different handling actions. For example, if it is judged as non-dangerous, no processing is done; for low-risk and medium-risk, warning processing is done; for high-risk, blocking processing is done. Users can customize rules by combining the value ranges of each dimension to set the danger levels in different scenarios, that is, set the preset risk judgment rules and risk handling rules; for example, 1. If the proportion of packets with a length of 1500Length exceeds 80% within the TCP communication time span for the same SMAC, the host is judged as high-risk; 2. If the proportion of packets with a length less than 80Length exceeds 75% within the TCP communication time span for the same SMAC, the host is judged as high-risk; 3. If the number of TCP requests initiated within one minute for the same SMAC exceeds 120 times, the host is judged as medium-risk; 4. If the number of TCP requests initiated within one minute for the same SMAC exceeds 500 times, the host is judged as high-risk; 5. If the TCP requests initiated in the early morning for the same SMAC account for more than 50% of the total requests, the host is judged as high-risk; the risk handling module: after the user sets the risk judgment rules, the system runs in the internal network for a period of time. All handling actions within this time range are warnings. The warning information clearly indicates which host it is and which rule is matched. The user needs to make an artificial judgment on its accuracy based on the warning information. If it is found that the host in the warning information will definitely not be compromised, it is marked as a false alarm. Set an expected threshold. If the overall proportion of false alarms reaches the expected threshold, reduce the value set in the rule, for example, reduce the proportion of packets with a length of 1500Length exceeding 80% within the TCP communication time span in the rule to 78%. On the contrary, if the overall proportion of false alarms does not reach the expected threshold, increase the value set in the rule, for example, increase it from 80% to 81%. After the learning cycle, if the host risk is judged as high-risk and the handling is blocking, the risk handling module calls the access control interface of the router in the internal network to create a rule to block the traffic of the compromised host.Performing the above blocking on the gateway router where the compromised host is located can prevent the spread of the compromised situation to other network areas at the network level. It should be noted that, additionally considering the impact of capturing too many packets for a long time on the router forwarding performance, the central scheduling module will call the router resource usage interface. If the resource utilization rates of CPU, memory, etc. are too high, the frequency of traffic collection will be reduced.
[0078] In summary, this application obtains a packet capture file through the packet capture function of network devices such as routers, parses the packets, and extracts features; users can customize rules by combining the value ranges of each dimension to set the risk levels in different scenarios; during the learning cycle, the rules are trained according to the false positives processed to improve the judgment accuracy; for the host judged to be compromised, performing the above blocking on the gateway router where the compromised host is located can prevent the spread of the compromised situation to other network areas at the network level.
[0079] See Figure 4 As shown, an intrusion detection and prevention device based on internal network traffic disclosed in an embodiment of this application includes:
[0080] A feature information acquisition module 11, configured to obtain a plurality of traffic packet files corresponding to a plurality of hosts, and parse the traffic packet files to obtain feature information in different dimensions;
[0081] A learning module 12, configured to obtain a preset risk judgment rule and a risk handling rule set for the host, and adjust the preset risk judgment rule within a preset learning cycle until the target risk judgment rule is obtained at the end of the preset learning cycle
[0082] A risk level judgment module 13, configured to judge the target risk level corresponding to the corresponding host based on the target risk judgment rule and according to the feature information;
[0083] A handling module 14, configured to determine the target handling method corresponding to the corresponding host based on the risk handling rule and according to the target risk level, and then perform handling on the corresponding host based on the target handling method.
[0084] Among them, for the more specific working processes of the above-mentioned various modules, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated here.
[0085] It can be seen that the present application obtains a number of traffic packet files corresponding to several hosts, parses the traffic packet files to obtain feature information in different dimensions; obtains preset risk judgment rules and risk handling rules set for the hosts, and adjusts the preset risk judgment rules within a preset learning period until the target risk judgment rules are obtained at the end of the preset learning period; based on the target risk judgment rules, and according to the feature information, determines the target risk level corresponding to the corresponding host; based on the risk handling rules, and according to the target risk level, determines the target handling method corresponding to the corresponding host, and then handles the corresponding host based on the target handling method. Thus, the present application performs intrusion detection and prevention by obtaining traffic packet files, reducing the invasiveness of the device; by continuously adjusting the preset risk judgment rules through a preset learning period, the accuracy and precision of intrusion detection and prevention can be improved.
[0086] Furthermore, an embodiment of the present application also provides an electronic device Figure 5 is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure should not be considered as any limitation to the scope of use of the present application.
[0087] Figure 5 is a structural schematic diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, an input / output interface 24, a communication interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps of the intrusion detection and prevention method based on intranet traffic disclosed in any of the foregoing embodiments.
[0088] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 25 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface 24 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is made here.
[0089] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, a random access memory, a disk, or an optical disc, etc. The memory 22 can include a random access memory as the operating memory and a non-volatile memory for storage purposes of external memory. The storage resources thereon include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0090] Among them, the operating system 221 is used to manage and control each hardware device and computer program 222 on the electronic device 20 on the source host. The operating system 221 can be Windows, Unix, Linux, etc. In addition to the computer program that can be used to complete the intrusion detection and prevention method based on intranet traffic executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 can further include computer programs that can be used to complete other specific tasks.
[0091] In this embodiment, the input / output interface 24 may specifically include, but is not limited to, a USB interface, a hard disk reading interface, a serial interface, a voice input interface, a fingerprint input interface, etc.
[0092] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the intrusion detection and prevention method based on intranet traffic disclosed above is implemented.
[0093] For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.
[0094] The computer-readable storage medium mentioned here includes random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, magnetic disks, or optical disks, or any other form of storage medium known in the technical field. Among them, when the computer program is executed by a processor, the foregoing intrusion detection and prevention method based on intranet traffic is implemented. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.
[0095] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the intrusion detection and prevention method based on intranet traffic disclosed in the embodiment, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part.
[0096] Those skilled in the art may further realize that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0097] The steps of the algorithms described in connection with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0098] Finally, it should also be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0099] The above has introduced in detail a method, device, equipment and medium for intrusion detection and prevention based on intranet traffic provided by the present invention. Specific examples are used in this document to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. An intrusion detection and prevention method based on intranet traffic, characterized in that, Including: Obtain a number of traffic packet files corresponding to a number of hosts, and parse the traffic packet files to obtain feature information in different dimensions; Obtain preset risk judgment rules and risk handling rules set for the hosts, and adjust the preset risk judgment rules within a preset learning period until the target risk judgment rules are obtained at the end of the preset learning period; Based on the target risk judgment rules, and according to the feature information, judge the target risk level corresponding to the corresponding host; Based on the risk handling rules, and according to the target risk level, determine the target handling method corresponding to the corresponding host, and then handle the corresponding host based on the target handling method; Wherein, the feature information includes the source MAC, source IP, packet type, packet size, and packet time corresponding to the traffic packet file; Wherein, based on the target risk judgment rules, and according to the feature information, judging the target risk level corresponding to the corresponding host includes: Determine the proportion of packet files in any specific situation of the same host according to the feature information; If the proportion of the packet files exceeds the preset threshold corresponding to the specific situation, determine the risk level corresponding to the preset threshold of the specific situation as the target risk level corresponding to the host.
2. The intrusion detection and prevention method based on intranet traffic according to claim 1, characterized in that The adjusting the preset risk judgment rules within a preset learning period until the target risk judgment rules are obtained at the end of the preset learning period includes: Based on the preset risk judgment rules, and according to the feature information, judge the reference risk level of the host; Construct reference alarm information based on target information; the target information includes the host identifier representing the host, the reference risk level, and the reference rule in the preset risk judgment rules for judging the host as the reference risk level; Obtain the judgment result of whether the alarm information is a false alarm by the client, adjust the reference rule according to the judgment result to obtain a new preset risk judgment rule, and then jump to the step based on the preset risk judgment rule until the target risk judgment rules are obtained at the end of the preset learning period.
3. The intrusion detection and prevention method based on intranet traffic according to claim 2, characterized in that, The preset risk judgment rules include a number of the reference rules; the reference rule is the risk corresponding to a target situation that satisfies a preset condition for a feature combination that stipulates different-dimensional feature information corresponding to the same host.
4. The intrusion detection and prevention method based on intranet traffic according to claim 3, characterized in that, The adjusting the reference rule according to the judgment result to obtain a new preset risk judgment rule includes: Determine the target proportion of false alarms in the judgment result; If the target proportion is different from the preset proportion, adjust the preset threshold of the feature combination corresponding to the reference rule to obtain a new preset risk judgment rule.
5. The intrusion detection and prevention method based on intranet traffic according to claim 1, wherein Also including: Adjust the frequency of the step of obtaining a number of traffic packet files corresponding to a number of hosts according to the utilization rate of the target resources corresponding to the host.
6. The intrusion detection and prevention method based on intranet traffic according to any one of claims 1 to 5, characterized in that, The obtaining a number of traffic packet files corresponding to a number of hosts includes: Obtain a number of traffic packet files corresponding to a number of hosts through a third-party interface provided by a target network device; Correspondingly, determining a target handling method corresponding to the corresponding host according to the target risk level, and then handling the corresponding host based on the target handling method, includes: If the target risk level is high risk, the target handling method is blocking processing, and the blocking processing of the host is executed in the target network device corresponding to the host to prevent the spread of the compromised situation at the network level; If the target risk level is low risk or medium risk, the target handling method is alarm processing. Based on the host identifier representing the host, the target risk level, and the target rule in the target risk judgment rule for determining the host as the target risk level, a target alarm message is constructed and sent to the client.
7. An intrusion detection and prevention device based on intranet traffic, characterized in that, Including: A feature information acquisition module, configured to acquire a plurality of traffic packet files corresponding to a plurality of hosts, and parse the traffic packet files to obtain feature information in different dimensions; A learning module, configured to acquire a preset risk judgment rule and a risk handling rule set for the host, and adjust the preset risk judgment rule within a preset learning period until the target risk judgment rule is obtained at the end of the preset learning period; A risk level judgment module, configured to judge the target risk level corresponding to the corresponding host based on the target risk judgment rule and according to the feature information; A handling module, configured to determine a target handling method corresponding to the corresponding host based on the risk handling rule and according to the target risk level, and then handle the corresponding host based on the target handling method; Wherein, the feature information includes the source MAC, source IP, packet type, packet size, and packet time corresponding to the traffic packet file; Wherein, the risk level judgment module is specifically configured to determine the proportion of the packet files in any specific situation of the same host according to the feature information; If the proportion of the packet files exceeds the preset threshold corresponding to the specific situation, the risk level corresponding to the preset threshold of the specific situation is determined as the target risk level corresponding to the host.
8. An electronic device, characterized in that, Including a processor and a memory; wherein, when the processor executes the computer program stored in the memory, the intrusion detection and prevention method based on intranet traffic according to any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium, characterized in that, For storing a computer program; wherein, when the computer program is executed by the processor, the intrusion detection and prevention method based on intranet traffic according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Network intrusion prevention method and device
CN105491063A
A false alarm behavior processing method and device
CN109815697A