Method and apparatus for network threat identification based on traffic flow
By performing dual threat identification at both the network and application layers on network traffic data and using a policy rule base to match parameter values, the problem of traditional security protection technologies being unable to identify unknown threats and diverse attacks is solved, thus achieving effective protection for enterprise network systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-21
- Publication Date
- 2026-04-07
AI Technical Summary
Traditional security technologies are unable to effectively identify and prevent unknown threats and diverse attacks in enterprise network systems, especially attacks through authorized business access points, which lead to security vulnerabilities in enterprise network systems.
By acquiring network traffic data to identify network layer threats and determining the target application category, application layer threats are identified using a policy rule base under a preset scenario. Parameter values in the network traffic data are matched to identify potential threats, and the system allows or blocks access based on the identification results.
It enables the effective identification and timely blocking of network traffic data in enterprise network systems, ensuring the long-term stable operation of business systems and enhancing the ability to protect against unknown threats and diverse attacks.
Smart Images

Figure CN115580441B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology and protection, and in particular to a method and apparatus for identifying network threats based on business flow. Background Technology
[0002] With the rapid development and widespread adoption of the internet, cyberattack techniques have undergone significant changes. They have shifted from known threats to unknown threats, from normal channels to evasive tactics, and from single-form attacks to diverse attack methods. Enterprise users may unknowingly become accomplices in attacks, and trust-based intrusions are more prevalent, meaning that most attacks may originate from authorized business access points. Traditional security technologies are no longer sufficient to address the challenges faced by enterprise network system security. Summary of the Invention
[0003] To address the aforementioned issues, this application provides a network threat identification method and apparatus based on service flow.
[0004] According to a first aspect of this application, a network threat identification method based on service flow is provided, comprising:
[0005] Acquire network traffic data under preset scenarios;
[0006] Perform network layer threat identification on the network traffic data to obtain the first threat identification result;
[0007] In response to the first threat identification result indicating that the network traffic data does not pose a threat, the target application category of the network traffic data is determined;
[0008] Based on the policy rule base under the preset scenario, and according to the target application category, the network traffic data is subjected to application layer threat identification to obtain a second threat identification result; wherein, the policy rule base includes threat matching rules corresponding to each application category under the preset scenario.
[0009] In some embodiments of this application, the step of performing application-layer threat identification on the network traffic data based on the policy rule base under the preset scenario and according to the target application category to obtain a second threat identification result includes:
[0010] Based on the target application category, at least one threat matching rule corresponding to the target application category is obtained from the policy rule base;
[0011] The network traffic data is broken down to determine the parameter values of each parameter in the network traffic data;
[0012] The parameter values of each parameter are matched sequentially with at least one threat matching rule;
[0013] In response to the successful match between the parameter values of each parameter and the target threat matching rule in the at least one threat matching rule, the second threat identification result is determined to be that the network traffic data is threatened;
[0014] In response to the fact that the parameter values of each parameter fail to match with the at least one threat matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data.
[0015] In other embodiments of this application, the policy rule base further includes security matching rules corresponding to the application category under the preset scenario; the step of performing application-layer threat identification on the network traffic data based on the policy rule base under the preset scenario and the target application category to obtain a second threat identification result includes:
[0016] Based on the target application category, at least one matching rule corresponding to the target application category is obtained from the policy rule base; the at least one matching rule includes at least one threat matching rule and / or a security matching rule;
[0017] The network traffic data is broken down to determine the parameter values of each parameter in the network traffic data;
[0018] The parameter values of each parameter are sequentially matched with at least one matching rule;
[0019] In response to the successful matching of the parameter values of each parameter with the target threat matching rule in the at least one matching rule, the second threat identification result is determined to be that the network traffic data is threatened;
[0020] In response to the successful matching of the parameter values of each parameter with the target security matching rule in the at least one matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data;
[0021] If the parameter values of each parameter fail to match with any of the at least one matching rules, the second threat identification result is determined to be that the network traffic data does not pose a threat.
[0022] In some embodiments of this application, the method further includes:
[0023] In response to the second threat identification result indicating that the network traffic data does not pose a threat, the network traffic data is allowed to proceed;
[0024] In response to the first threat identification result indicating that the network traffic data is threatening, or the second threat identification result indicating that the network traffic data is threatening, the network traffic data is blocked.
[0025] The construction process of the policy rule base includes:
[0026] Obtain network traffic data samples that pose a threat within a preset time range under the preset scenario;
[0027] The network traffic data samples are categorized by application type;
[0028] The network traffic data samples under each application category are decomposed to obtain the parameter values of each parameter in the network traffic data samples under each application category;
[0029] Based on preset syntax rules, the system performs unified compilation processing on the parameter values of each parameter in the network traffic data samples under each application category to obtain the matching rules corresponding to each application category.
[0030] According to a second aspect of this application, a network threat identification device based on service flow is provided, comprising:
[0031] The first acquisition module is used to acquire network traffic data under a preset scenario;
[0032] The second acquisition module is used to perform network layer threat identification on the network traffic data and acquire the first threat identification result;
[0033] The determination module is configured to determine the target application category of the network traffic data in response to the first threat identification result indicating that the network traffic data does not pose a threat;
[0034] The third acquisition module is used to perform application-layer threat identification on the network traffic data based on the policy rule base under the preset scenario and the target application category, and to obtain a second threat identification result; wherein, the policy rule base includes threat matching rules corresponding to each application category under the preset scenario.
[0035] In some embodiments of this application, the third acquisition module is specifically used for:
[0036] Based on the target application category, at least one threat matching rule corresponding to the target application category is obtained from the policy rule base;
[0037] The network traffic data is broken down to determine the parameter values of each parameter in the network traffic data;
[0038] The parameter values of each parameter are matched sequentially with at least one threat matching rule;
[0039] In response to the successful match between the parameter values of each parameter and the target threat matching rule in the at least one threat matching rule, the second threat identification result is determined to be that the network traffic data is threatened;
[0040] In response to the fact that the parameter values of each parameter fail to match with the at least one threat matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data.
[0041] In other embodiments of this application, the policy rule base further includes security matching rules corresponding to the application category under the preset scenario; the third acquisition module is specifically used for:
[0042] Based on the target application category, at least one matching rule corresponding to the target application category is obtained from the policy rule base; the at least one matching rule includes at least one threat matching rule and / or a security matching rule;
[0043] The network traffic data is broken down to determine the parameter values of each parameter in the network traffic data;
[0044] The parameter values of each parameter are sequentially matched with at least one matching rule;
[0045] In response to the successful matching of the parameter values of each parameter with the target threat matching rule in the at least one matching rule, the second threat identification result is determined to be that the network traffic data is threatened;
[0046] In response to the successful matching of the parameter values of each parameter with the target security matching rule in the at least one matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data;
[0047] If the parameter values of each parameter fail to match with any of the at least one matching rules, the second threat identification result is determined to be that the network traffic data does not pose a threat.
[0048] In some embodiments of this application, the apparatus further includes:
[0049] The allow module is used to allow the network traffic data to pass in response to the second threat identification result indicating that the network traffic data does not pose a threat;
[0050] The blocking module is configured to block the network traffic data in response to either the first threat identification result indicating that the network traffic data poses a threat, or the second threat identification result indicating that the network traffic data poses a threat.
[0051] In addition, the device also includes a construction module, which is specifically used for:
[0052] Obtain network traffic data samples that pose a threat within a preset time range under the preset scenario;
[0053] The network traffic data samples are categorized by application type;
[0054] The network traffic data samples under each application category are decomposed to obtain the parameter values of each parameter in the network traffic data samples under each application category;
[0055] Based on preset syntax rules, the system performs unified compilation processing according to the parameter values of each parameter in the network traffic data sample under each application category to obtain the matching rules corresponding to each application category, thereby constructing the policy rule library.
[0056] According to a third aspect of this application, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, it implements the method described in the first aspect above.
[0057] According to a fourth aspect of this application, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the method described in the first aspect above.
[0058] According to the technical solution of this application, for network traffic data under a preset scenario, network layer threat identification is first performed to obtain a first threat identification result. If the first threat identification result indicates that there is no threat in the network traffic data, the target application category of the network traffic data is determined. Based on the policy rule base under the preset scenario, application layer threat identification is performed on the network traffic data according to the target application category to obtain a second threat identification result. This solution, in addition to performing network layer threat identification on network traffic data under the preset scenario, also performs application layer threat identification on the network traffic data. This enables effective identification of network traffic data under relevant business scenarios, facilitating timely blocking and interception of threatening network access, and ensuring the long-term stable operation of business systems under the preset scenario.
[0059] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description
[0060] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein:
[0061] Figure 1 A flowchart illustrating a network threat identification method based on service flow provided in this application embodiment;
[0062] Figure 2 This is a flowchart illustrating application-layer threat identification of network traffic data in an embodiment of this application;
[0063] Figure 3 This is a flowchart illustrating another application-layer threat identification process for network traffic data in this application embodiment;
[0064] Figure 4 This is a flowchart illustrating the construction process of a policy rule base in one embodiment of this application;
[0065] Figure 5 A structural block diagram of a network threat identification device based on service traffic provided in this application embodiment;
[0066] Figure 6 This is a structural block diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0067] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this application, and should not be construed as limiting this application.
[0068] It should be noted that in enterprise network systems, with the increasing complexity of interconnected networks and large-scale cross-network applications, it is becoming increasingly difficult to grasp the online behavior of various application services within the network, and to discover the true challenges and risks faced in the network environment. At the same time, in terms of security protection technology, the prevalence of new forms of malware and zero-day attacks has rendered traditional antivirus, anti-hacking, and endpoint protection mechanisms (signature matching) almost ineffective.
[0069] With the rapid development and widespread adoption of the internet, cyberattack techniques have undergone significant changes. They have shifted from known threats to unknown threats, from normal channels to evasive tactics, and from single-form attacks to diverse attack methods. Enterprise users may unknowingly become accomplices in attacks, and trust-based intrusions are more prevalent, meaning that most attacks may originate from authorized business access points. Traditional security technologies are no longer sufficient to address the challenges faced by enterprise network system security.
[0070] As enterprise network structures expand, the environments in which they face cyberattacks are also changing. It's no longer just about setting up internal LANs, WANs, or DMZs; it can also involve large LANs composed of various departments, branch offices, or partners. Such networks may experience increased risks due to the higher level of trust required. A breach in one area can plunge the entire network into crisis. Because attackers' techniques and objectives have changed, they are more familiar with the functions, performance, and deployment rules of traditional perimeter security devices. Therefore, they target traditional perimeter security devices by exploiting system vulnerabilities to attack servers or PCs, implanting Trojans through allowed ports. They can even alter attack signatures to make them undetectable by perimeter security devices, and exploit machines within the LAN to obtain confidential information. Such attacks are difficult to prevent effectively.
[0071] To address the aforementioned issues, this application provides a network threat identification method and apparatus based on service flow.
[0072] Figure 1 This is a flowchart illustrating a network threat identification method based on service flow, provided in an embodiment of this application. It should be noted that the network threat identification method based on service flow of this application can be used in the network threat identification device based on service flow of this application, and the network threat identification device based on service flow of this application can be configured in an electronic device. Figure 1 As shown, the network threat identification method based on service flow in this application embodiment may include the following steps:
[0073] Step 101: Obtain network traffic data under the preset scenario.
[0074] In some embodiments of this application, the preset scenario can be a business scenario within an enterprise or a department, or a business scenario within an enterprise or a department within a corresponding time range. The network traffic data under the preset scenario is the network traffic data generated in real time under the preset scenario.
[0075] Step 102: Perform network layer threat identification on the network traffic data to obtain the first threat identification result.
[0076] Network layer threat identification refers to traditional network threat identification methods, such as identifying whether network traffic data contains threats through protocols, IP addresses, and port numbers. The first threat identification result is the result after network layer threat identification, including whether the network traffic data contains a threat or not.
[0077] Step 103: In response to the first threat identification result indicating that there is no threat to the network traffic data, determine the target application category of the network traffic data.
[0078] It's understandable that network layer threat identification alone cannot detect some network tools with evasive tactics. For example, attacks can exploit system vulnerabilities and open ports to attack servers or PCs, thereby implanting Trojans and other network attacks. Network layer threat identification alone cannot solve system security problems. To further identify threats in network traffic data, even if the initial threat identification result indicates no threat in the network traffic data, application layer threat identification is performed to effectively prevent similar attacks.
[0079] In some embodiments of this application, since the identified network traffic data occurs within a preset scenario, the network traffic data can be categorized by application type based on this scenario, such as covering social applications, conferencing applications, etc. Because the threats present in the network traffic data under each application category share commonalities, the target application category of the network traffic data can be determined first, and then application-layer threat identification can be performed. Typically, the target application category of the network traffic data can be determined based on the protocol corresponding to the network traffic data.
[0080] Step 104: Based on the policy rule base under the preset scenario, perform application layer threat identification on network traffic data according to the target application category to obtain the second threat identification result; wherein, the policy rule base includes threat matching rules corresponding to each application category under the preset scenario.
[0081] In some embodiments of this application, a corresponding policy rule base can be formulated based on network traffic data within a certain period of time under a preset scenario. This policy rule base includes threat matching rules corresponding to various application categories under the preset scenario. Specifically, it extracts features from network traffic data samples containing threats within a certain period under the preset scenario and compiles them into corresponding threat matching rules. Furthermore, the policy rule base under the preset scenario can be continuously updated.
[0082] As one implementation method, the process of application-layer threat identification of network traffic data may include: obtaining at least one threat matching rule corresponding to the target application category from a policy rule base; matching the network traffic data with the at least one threat matching rule; if a threat matching rule is successfully matched with the network traffic data, the second threat identification result is that there is a threat in the network traffic data; if the network traffic data is not successfully matched with any of the at least one threat matching rules, the second threat identification result is that there is no threat in the network traffic data.
[0083] In some embodiments of this application, after threat identification of network traffic data, corresponding processing is required based on the identification results to promptly block and intercept network threats such as vulnerability attacks, viruses, and password brute-force attacks. Therefore, the method may further include:
[0084] Step 105: In response to the second threat identification result indicating that there is no threat to the network traffic data, the network traffic data is allowed to pass.
[0085] Step 106: In response to the first threat identification result indicating that the network traffic data is threatened, or the second threat identification result indicating that the network traffic data is threatened, the network traffic data is blocked.
[0086] In some embodiments of this application, if either the first threat identification result or the second threat identification result indicates that the network traffic data poses a threat, while blocking the network traffic, relevant information about the network traffic data can also be written to a log to facilitate subsequent analysis of the identification results. The content written to the log may include the network traffic data, application category, and threat matching rules if a match is found with the network traffic data.
[0087] According to the network threat identification method based on business flow in this application, for network traffic data under a preset scenario, network layer threat identification is first performed to obtain a first threat identification result. If the first threat identification result indicates that there is no threat in the network traffic data, the target application category of the network traffic data is determined. Based on the policy rule base under the preset scenario, application layer threat identification is performed on the network traffic data according to the target application category to obtain a second threat identification result. This solution, in addition to performing network layer threat identification on network traffic data under the preset scenario, also performs application layer threat identification on the network traffic data. This enables effective identification of network traffic data under relevant business scenarios, facilitating timely blocking and interception of threatening network access, and ensuring the long-term stable operation of the business system under the preset scenario.
[0088] Next, we will provide a detailed introduction to the process of identifying application-layer threats in network traffic data based on the policy rule base under a preset scenario and according to the target application category, and obtaining the results of secondary threat identification.
[0089] Figure 2 This is a flowchart illustrating application-layer threat identification of network traffic data in an embodiment of this application. Figure 2 As shown, based on the above embodiments, Figure 1 The implementation of step 104 may include the following steps:
[0090] Step 201: Based on the target application category, obtain at least one threat matching rule corresponding to the target application category from the policy rule base.
[0091] Step 202: Decompose the network traffic data and determine the parameter values of each parameter in the network traffic data.
[0092] Step 203: Match the parameter values of each parameter with at least one threat matching rule in sequence.
[0093] The threat matching rules are compiled uniformly based on the parameter values of each parameter in the network traffic data sample containing threats. Therefore, if the parameter value of each parameter in the network traffic data matches a rule in at least one of the threat matching rules, it indicates that there is a threat in the network traffic data; otherwise, it indicates that there is no threat in the network traffic data.
[0094] Step 204: In response to the successful matching of the parameter values of each parameter with the target threat matching rule in at least one threat matching rule, the second threat identification result is determined to be a threat to the network traffic data.
[0095] Step 205: In response to the fact that the parameter values of each parameter do not match with at least one threat matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data.
[0096] According to the network threat identification method based on business flow in this application embodiment, at least one threat matching rule corresponding to the target application category is obtained from a policy rule base. The network traffic data is then broken down to determine the parameter values of each parameter. Each parameter value is matched against at least one threat matching rule. If the parameter value matches the target threat matching rule, the network traffic data is determined to pose a threat; otherwise, no threat exists. By matching with the matching rules in the policy rule base, threat identification of the network traffic data is further performed. This enables effective identification of network traffic data in relevant business scenarios, facilitating timely blocking of threatening network access and ensuring the long-term stable operation of the business system under preset scenarios.
[0097] In some other embodiments of this application, the policy rule base also includes security matching rules corresponding to application categories under preset scenarios. These security matching rules refer to network traffic data that satisfies the matching rule as secure. These security matching rules can be uniformly compiled based on the parameter values of various parameters in obviously secure network traffic data samples. By adding security matching rules, the matching speed in the application layer threat identification process of network traffic data can be improved.
[0098] Figure 3This is another flowchart illustrating application-layer threat identification of network traffic data in an embodiment of this application. Figure 3 As shown, based on the above embodiments, Figure 1 The implementation of step 104 may include the following steps:
[0099] Step 301: Based on the target application category, obtain at least one matching rule corresponding to the target application category from the policy rule base; the at least one matching rule includes at least one threat matching rule and / or a security matching rule.
[0100] Step 302: Decompose the network traffic data and determine the parameter values of each parameter in the network traffic data.
[0101] Step 303: Match the parameter values of each parameter with at least one matching rule in sequence.
[0102] Step 304: In response to the successful matching of the parameter values of each parameter with the target threat matching rule in at least one matching rule, the second threat identification result is determined to be a threat to the network traffic data.
[0103] Step 305: In response to the successful matching of the parameter values of each parameter with the target security matching rule in at least one matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data.
[0104] Step 306: In response to the fact that the parameter values of each parameter do not match with at least one matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data.
[0105] According to the network threat identification method based on service flow in this application embodiment, the speed of the matching process can be improved by adding security matching rules corresponding to application categories to the policy rule base, thereby improving the efficiency of network threat identification.
[0106] Next, we will introduce the construction process of the policy rule base under the preset scenario.
[0107] Figure 4 This is a flowchart illustrating the construction process of a policy rule base in one embodiment of this application. Figure 4 As shown, the construction process includes:
[0108] Step 401: Obtain network traffic data samples that pose a threat within a preset time range under a preset scenario.
[0109] Step 402: Divide the network traffic data samples into application categories.
[0110] Step 403: Decompose the network traffic data sample under each application category and obtain the parameter values of each parameter in the network traffic data sample under each application category.
[0111] Step 404: Based on the preset syntax rules, perform unified compilation processing according to the parameter values of each parameter in the network traffic data sample under each application category to obtain the matching rules corresponding to each application category.
[0112] As an example, the preset syntax rules can be shown in Table 1, and the preset syntax rules can be similar to traditional regular expression rules.
[0113] Table 1 Examples of Preset Syntax Rules
[0114]
[0115] In some embodiments of this application, the policy rule base may also include security matching rules. For example, features of obviously secure network traffic data can be extracted, that is, the parameter values of each parameter in obviously secure network traffic data under the corresponding application category can be uniformly compiled according to preset syntax rules to obtain the corresponding security matching rules. In addition, the threat matching rules in the policy rule base can also be combined with virus signature databases, vulnerability databases, URL databases, IP blacklist databases, etc.
[0116] According to the network threat identification method based on business flow in this application, the matching rules of business data flow are uniformly compiled based on preset syntax rules to construct a policy rule base under preset scenarios, so as to realize multi-level threat identification based on business data flow, so as to block and intercept network access with threats in a timely manner and ensure the long-term stable operation of business systems under preset scenarios.
[0117] To implement the above embodiments, this application provides a network threat identification device based on service flow.
[0118] Figure 5 This is a structural block diagram of a network threat identification device based on service traffic, provided as an embodiment of this application. Figure 5 As shown, the device includes:
[0119] The first acquisition module 501 is used to acquire network traffic data under a preset scenario;
[0120] The second acquisition module 502 is used to perform network layer threat identification on network traffic data and obtain the first threat identification result;
[0121] The determination module 503 is used to determine the target application category of the network traffic data in response to the first threat identification result indicating that there is no threat in the network traffic data;
[0122] The third acquisition module 504 is used to perform application layer threat identification on network traffic data based on the policy rule base under the preset scenario and the target application category, and to obtain the second threat identification result; wherein, the policy rule base includes threat matching rules corresponding to each application category under the preset scenario.
[0123] In some embodiments of this application, the third acquisition module 504 is specifically used for:
[0124] Based on the target application category, retrieve at least one threat matching rule corresponding to the target application category from the policy rule base;
[0125] Decompose network traffic data to determine the parameter values of each parameter in the network traffic data;
[0126] The parameter values of each parameter are matched sequentially with at least one threat matching rule;
[0127] If the parameter values of each parameter are successfully matched with the target threat matching rule in at least one threat matching rule, the second threat identification result is determined to be a threat to the network traffic data;
[0128] Since the parameter values of each parameter failed to match with at least one threat matching rule, the second threat identification result was determined to be that there was no threat in the network traffic data.
[0129] In other embodiments of this application, the policy rule base also includes security matching rules corresponding to application categories under preset scenarios; the third acquisition module 504 is specifically used for:
[0130] Based on the target application category, at least one matching rule corresponding to the target application category is obtained from the policy rule base; the at least one matching rule includes at least one threat matching rule and / or a security matching rule;
[0131] Decompose network traffic data to determine the parameter values of each parameter in the network traffic data;
[0132] Each parameter value is matched sequentially with at least one matching rule;
[0133] If the parameter values of each parameter are successfully matched with the target threat matching rule in at least one matching rule, the second threat identification result is determined to be a threat to the network traffic data;
[0134] If the parameter values of each parameter successfully match the target security matching rule in at least one matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data;
[0135] Since the parameter values of each parameter failed to match with at least one matching rule, the second threat identification result was determined to be that there was no threat in the network traffic data.
[0136] In some embodiments of this application, the apparatus further includes:
[0137] The allow module 505 is used to allow network traffic data to pass in response to the second threat identification result indicating that there is no threat to the network traffic data;
[0138] The blocking module 506 is used to block network traffic data in response to a first threat identification result indicating that the network traffic data is a threat, or a second threat identification result indicating that the network traffic data is a threat.
[0139] In addition, the device also includes a construction module, which 507 is specifically used for:
[0140] Acquire network traffic data samples that pose a threat within a preset time range under a preset scenario;
[0141] Classify network traffic data samples by application category;
[0142] The network traffic data samples under each application category are broken down to obtain the parameter values of each parameter in the network traffic data samples under each application category;
[0143] Based on preset syntax rules, the system performs unified compilation processing on the parameter values of each parameter in the network traffic data samples under each application category to obtain the matching rules corresponding to each application category, thereby constructing a policy rule library.
[0144] According to the network threat identification device based on business flow in this application embodiment, for network traffic data under a preset scenario, first, network layer threat identification is performed to obtain a first threat identification result. If the first threat identification result indicates that there is no threat in the network traffic data, the target application category of the network traffic data is determined. Based on the policy rule base under the preset scenario, application layer threat identification is performed on the network traffic data according to the target application category to obtain a second threat identification result. This solution, in addition to performing network layer threat identification on network traffic data under the preset scenario, also performs application layer threat identification on the network traffic data. This enables effective identification of network traffic data under relevant business scenarios, facilitating timely blocking and interception of threatening network access, and ensuring the long-term stable operation of the business system under the preset scenario.
[0145] Figure 6This is a structural block diagram of an electronic device for a network threat identification method based on traffic flow according to an embodiment of this application. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present application described and / or claimed herein.
[0146] like Figure 6 As shown, the electronic device includes a memory 610, a processor 620, and a computer program 630 stored in the memory and executable on the processor. The various components are interconnected via different buses and can be mounted on a common motherboard or otherwise as required. The processor can process instructions executed within the electronic device, including instructions stored in or on the memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to an interface). In other embodiments, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple electronic devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system).
[0147] The memory 610 is the non-transitory computer-readable storage medium provided in this application. The memory stores instructions executable by at least one processor to cause the at least one processor to perform the methods of the above embodiments. The non-transitory computer-readable storage medium of this application stores computer instructions for causing a computer to perform the methods described in the above embodiments.
[0148] The memory 610, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the program instructions / modules corresponding to the methods in the above embodiments. The processor 620 executes various functional applications and data processing of the server by running the non-transitory software programs, instructions, and modules stored in the memory 610, thereby implementing the methods in the above embodiments.
[0149] The memory 610 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the electronic device for implementing the methods in the above embodiments. Furthermore, the memory 610 may include high-speed random access memory and may also include non-transient memory, such as at least one disk storage device, flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory 610 may optionally include memory remotely located relative to the processor 620, and these remote memories can be connected via a network to the electronic device for implementing the methods in the above embodiments. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0150] The electronic device used in the methods described in the above embodiments may further include an input device 640 and an output device 650. The processor 620, memory 610, input device 640, and output device 650 may be connected via a bus or other means. Figure 6 Taking the example of a connection between China and Israel via a bus.
[0151] Input device 640 can receive input numerical or character information, and generate key signal inputs related to user settings and function control of the electronic device, such as a touch screen, keypad, mouse, trackpad, touchpad, joystick, one or more mouse buttons, trackball, joystick, etc. Output device 650 may include a display device, auxiliary lighting device (e.g., LED), and haptic feedback device (e.g., vibration motor). The display device may include, but is not limited to, a liquid crystal display (LCD), a light-emitting diode (LED) display, and a plasma display. In some embodiments, the display device may be a touch screen.
[0152] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0153] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0154] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.
[0155] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.
[0156] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0157] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.
[0158] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.
[0159] The storage medium mentioned above can be a read-only memory, a disk, or an optical disk, etc. Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.
Claims
1. A network threat identification method based on service flow, characterized in that, include: Acquire network traffic data under preset scenarios; Perform network layer threat identification on the network traffic data to obtain the first threat identification result; In response to the first threat identification result indicating that there is no threat in the network traffic data, the target application category of the network traffic data is determined; Based on the policy rule base under the preset scenario, and according to the target application category, the network traffic data is subjected to application layer threat identification to obtain a second threat identification result; wherein, the policy rule base includes threat matching rules corresponding to each application category under the preset scenario, and the policy rule base is continuously updated; If the second threat identification result indicates that the network traffic data does not pose a threat, then the network traffic data is allowed to pass through. In response to the first threat identification result indicating that the network traffic data is threatening, or the second threat identification result indicating that the network traffic data is threatening, the network traffic data is blocked. The construction process of the policy rule base includes: Obtain network traffic data samples that pose a threat within a preset time range under the preset scenario; The network traffic data samples are categorized by application type; The network traffic data samples under each application category are decomposed to obtain the parameter values of each parameter in the network traffic data samples under each application category; Based on preset syntax rules, the system performs unified compilation processing according to the parameter values of each parameter in the network traffic data sample under each application category to obtain the matching rules corresponding to each application category.
2. The method according to claim 1, characterized in that, The policy rule base based on the preset scenario, according to the target application category, performs application-layer threat identification on the network traffic data to obtain a second threat identification result, including: Based on the target application category, at least one threat matching rule corresponding to the target application category is obtained from the policy rule base; The network traffic data is broken down to determine the parameter values of each parameter in the network traffic data; The parameter values of each parameter are matched sequentially with at least one threat matching rule; In response to the successful match between the parameter values of each parameter and the target threat matching rule in the at least one threat matching rule, the second threat identification result is determined to be that the network traffic data is threatened; In response to the fact that the parameter values of each parameter fail to match with the at least one threat matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data.
3. The method according to claim 1, characterized in that, The policy rule base also includes security matching rules corresponding to the application categories under the preset scenario; the process of performing application-layer threat identification on the network traffic data based on the policy rule base under the preset scenario and the target application category to obtain a second threat identification result includes: Based on the target application category, at least one matching rule corresponding to the target application category is obtained from the policy rule base; the at least one matching rule includes at least one threat matching rule and / or a security matching rule; The network traffic data is broken down to determine the parameter values of each parameter in the network traffic data; The parameter values of each parameter are sequentially matched with at least one matching rule; In response to the successful matching of the parameter values of each parameter with the target threat matching rule in the at least one matching rule, the second threat identification result is determined to be that the network traffic data is threatened; In response to the successful matching of the parameter values of each parameter with the target security matching rule in the at least one matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data; If the parameter values of each parameter fail to match with any of the at least one matching rules, the second threat identification result is determined to be that the network traffic data does not pose a threat.
4. A network threat identification device based on service flow, characterized in that, include: The first acquisition module is used to acquire network traffic data under a preset scenario; The second acquisition module is used to perform network layer threat identification on the network traffic data, and then acquire the first threat identification result; The determination module is configured to determine the target application category of the network traffic data in response to the first threat identification result indicating that the network traffic data does not pose a threat; The third acquisition module is used to perform application-layer threat identification on the network traffic data based on the policy rule base under the preset scenario and the target application category, and to obtain a second threat identification result; wherein, the policy rule base includes threat matching rules corresponding to each application category under the preset scenario, and the policy rule base is continuously updated; The allow module is configured to allow the network traffic data to pass if the second threat identification result indicates that the network traffic data does not pose a threat. The blocking module is configured to block the network traffic data in response to either the first threat identification result indicating that the network traffic data poses a threat, or the second threat identification result indicating that the network traffic data poses a threat. The construction module is used to: acquire network traffic data samples that pose a threat within a preset time range under the preset scenario; classify the network traffic data samples into application categories; decompose the network traffic data samples under each application category to obtain the parameter values of each parameter in the network traffic data samples under each application category; and perform unified compilation processing based on preset syntax rules and the parameter values of each parameter in the network traffic data samples under each application category to obtain the matching rules corresponding to each application category, so as to construct the policy rule library.
5. The apparatus according to claim 4, characterized in that, The third acquisition module is specifically used for: Based on the target application category, at least one threat matching rule corresponding to the target application category is obtained from the policy rule base; The network traffic data is broken down to determine the parameter values of each parameter in the network traffic data; The parameter values of each parameter are matched sequentially with at least one threat matching rule; In response to the successful match between the parameter values of each parameter and the target threat matching rule in the at least one threat matching rule, the second threat identification result is determined to be that the network traffic data is threatened; In response to the fact that the parameter values of each parameter fail to match with the at least one threat matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data.
6. The apparatus according to claim 4, characterized in that, The policy rule base also includes security matching rules corresponding to the application categories under the preset scenario; the third acquisition module is specifically used for: Based on the target application category, at least one matching rule corresponding to the target application category is obtained from the policy rule base; the at least one matching rule includes at least one threat matching rule and / or a security matching rule; The network traffic data is broken down to determine the parameter values of each parameter in the network traffic data; The parameter values of each parameter are sequentially matched with at least one matching rule; In response to the successful matching of the parameter values of each parameter with the target threat matching rule in the at least one matching rule, the second threat identification result is determined to be that the network traffic data is threatened; In response to the successful matching of the parameter values of each parameter with the target security matching rule in the at least one matching rule, the second threat identification result is determined to be that there is no threat in the network traffic data; If the parameter values of each parameter fail to match with any of the at least one matching rules, the second threat identification result is determined to be that the network traffic data does not pose a threat.
7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method as described in any one of claims 1 to 3.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Threat detection method based on deep protocol analysis
CN109995740A
Data detection method and device and storage medium
CN111447215A
Access control method and device and gateway
CN111865976A
Network attack detection method and system based on traffic analysis
CN114338233A