Network attack detection method, device, system and storage medium

CN115834238BActive Publication Date: 2026-08-07CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM NETWORK SECURITY TECH CO LTD
Filing Date
2022-12-23
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

然而,该种检测网络攻击的方式,在响应与攻击时都有延迟时间,很可能使得当RST到达会话端点时,对应的TCP会话可能早已结束,从而导致会话阻断失败,同时当面临大流量数据包处理时,检测性能容易出现瓶颈

Benefits of technology

[0069] In this embodiment, a tiered detection approach is used to perform attack detection on traffic information sent by network devices. This effectively enables in-depth detection of specific traffic, resulting in more accurate attack identification. Furthermore, by setting up multi-level detection methods, such as rule-based detection, transport layer feature detection, and application layer feature detection of traffic information, tiered processing of network traffic can be effectively achieved, significantly improving performance throughput. In addition, this application dynamically optimizes rules and models by reviewing historical judgment times, making the attack detection model more adaptable, effectively shortening the overall response time, improving the blocking success rate, and thus enhancing network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834238B_ABST
    Figure CN115834238B_ABST
Patent Text Reader

Abstract

The application discloses a network attack detection method, device, system and storage medium, and relates to the technical field of network security. The method comprises the following steps: acquiring traffic information of a target network device to be detected; performing hierarchical detection processing on the traffic information; when any detection level is determined as an attack behavior, stopping the detection processing of the next level, and sending a blocking link to the target network device. The application can effectively realize deep detection of specific traffic, and the attack determination is more accurate. Furthermore, by setting multiple detection levels, for example, by performing rule detection, transport layer feature detection and application layer feature detection on the traffic information, hierarchical processing of network traffic can be effectively realized, and the performance throughput is significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, specifically to a network attack detection method, device, system, and storage medium. Background Technology

[0002] In the process of using the Internet, various network attacks are frequently encountered. In order to ensure network security and normal network access, effective network attack detection is essential.

[0003] Currently, the primary method for detecting network attacks is to use Intrusion Detection System (IDS) devices for monitoring. When the IDS detects an illegal connection, it sends a TCP RESET packet to both ends of the communication, thus proactively severing the connection. However, this method of detecting network attacks has delays in both response and attack, which may mean that by the time the RST reaches the session endpoint, the corresponding TCP session may have already ended, leading to session blocking failure. Furthermore, detection performance can easily become a bottleneck when dealing with large volumes of data packets.

[0004] Therefore, in order to better safeguard network security, timely and effective detection of network attacks is an urgent problem to be solved. Summary of the Invention

[0005] This application provides a network attack detection method, apparatus, system, and storage medium to improve the accuracy and timeliness of network attacks.

[0006] Firstly, a method for detecting network attacks is provided, the method comprising:

[0007] Obtain traffic information of the target network device under inspection;

[0008] The traffic information is subjected to hierarchical detection and processing;

[0009] When any detection level determines that an attack has occurred, the next level of detection processing is stopped, and a link blocking message is sent to the target network device.

[0010] In some optional implementations, the hierarchical detection processing of the traffic information includes:

[0011] The traffic information is detected and processed sequentially by the first-layer judgment model, the second-layer judgment model, and the third-layer judgment model in the deployed attack detection module.

[0012] The first-layer judgment model is used to determine attacks on the field rules of the traffic information.

[0013] The second-layer judgment model is used to determine the attack characteristics of the traffic information at the transport layer.

[0014] The third-layer judgment model is used to determine the attack characteristics of the traffic information at the application layer.

[0015] In some optional implementations, attack determination is performed on the field rules of the traffic information using the first-layer determination model, including:

[0016] The field rules of the traffic information are obtained through the field rule processing module in the first-layer judgment model;

[0017] The rule determination module in the first-layer determination model determines the field rules of the traffic information.

[0018] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the traffic information is sent to the second-layer determination model.

[0019] In some optional implementations, the transport layer characteristics of the traffic information are attacked using the second-layer determination model, including:

[0020] The transport layer features of the traffic information are obtained through the transport layer feature processing module in the second-layer determination model.

[0021] The transport layer characteristics of the traffic information are determined by the transport layer determination module in the second-layer determination model.

[0022] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the traffic information is sent to the third-layer determination model.

[0023] In some optional implementations, the third-layer determination model is used to determine the application layer characteristics of the traffic information for attack purposes, including:

[0024] The application layer features of the traffic information are obtained through the application layer feature processing module in the third-layer judgment model.

[0025] The application layer determination module in the third-layer determination model determines the application layer characteristics of the traffic information.

[0026] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the network attack detection operation is terminated.

[0027] In some optional implementations, the method further includes:

[0028] Based on historical blocking information, the attack detection module is dynamically optimized, and the attack judgment strategy of each layer judgment model is updated.

[0029] In some optional implementations, the dynamic optimization of the attack detection module based on historical blocking information and the updating of the attack determination strategy for each layer of the determination model include:

[0030] Adjust the field rules of the first-layer judgment model, as well as the transmission layer features and application layer features of the collected traffic information;

[0031] The acquired transport layer features and application layer features are then cropped.

[0032] The second-layer decision model is retrained and iterated based on the pruned transport layer features, and the third-layer decision model is retrained and iterated based on the pruned application layer features.

[0033] In some optional implementations, before dynamically optimizing the attack detection module based on historical blocking information and updating the attack determination strategy of each layer of the determination model, the method further includes:

[0034] The delay in blocking the traffic information is collected;

[0035] The delay percentage is determined to exceed a delay threshold. Secondly, a network attack detection device is provided, comprising:

[0036] The acquisition unit is used to acquire traffic information of the target network device to be detected.

[0037] A graded detection unit is used for graded detection and processing of the traffic information;

[0038] The processing unit is used to stop the next level of detection processing and send a blocking link to the target network device when any detection level determines that an attack has occurred.

[0039] In some optional implementations, the grading detection unit is specifically used for:

[0040] The traffic information is detected and processed sequentially by the first-layer judgment model, the second-layer judgment model, and the third-layer judgment model in the deployed attack detection module.

[0041] The first-layer judgment model is used to determine attacks on the field rules of the traffic information.

[0042] The second-layer judgment model is used to determine the attack characteristics of the traffic information at the transport layer.

[0043] The third-layer judgment model is used to determine the attack characteristics of the traffic information at the application layer.

[0044] In some optional implementations, the grading detection unit is specifically used for:

[0045] The field rules of the traffic information are obtained through the field rule processing module in the first-layer judgment model;

[0046] The rule determination module in the first-layer determination model determines the field rules of the traffic information.

[0047] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the traffic information is sent to the second-layer determination model.

[0048] In some optional implementations, the grading detection unit is specifically used for:

[0049] The transport layer features of the traffic information are obtained through the transport layer feature processing module in the second-layer determination model.

[0050] The transport layer characteristics of the traffic information are determined by the transport layer determination module in the second-layer determination model.

[0051] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the traffic information is sent to the third-layer determination model.

[0052] In some optional implementations, the grading detection unit is specifically used for:

[0053] The application layer features of the traffic information are obtained through the application layer feature processing module in the third-layer judgment model.

[0054] The application layer determination module in the third-layer determination model determines the application layer characteristics of the traffic information.

[0055] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the network attack detection operation is terminated.

[0056] In some optional implementations, the processing unit is further configured to:

[0057] Based on historical blocking information, the attack detection module is dynamically optimized, and the attack judgment strategy of each layer judgment model is updated.

[0058] In some optional implementations, the processing unit is specifically used for:

[0059] Adjust the field rules of the first-layer judgment model, as well as the transmission layer features and application layer features of the collected traffic information;

[0060] The acquired transport layer features and application layer features are then cropped.

[0061] The second-layer decision model is retrained and iterated based on the pruned transport layer features, and the third-layer decision model is retrained and iterated based on the pruned application layer features.

[0062] In some optional implementations, the processing unit is further configured to:

[0063] The delay in blocking the traffic information is collected;

[0064] It is determined that the percentage of delay exceeds the delay threshold.

[0065] Thirdly, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of any of the above methods.

[0066] Fourthly, a computer storage medium is provided that stores computer program instructions thereon, which, when executed by a processor, implement the steps of any of the above methods.

[0067] Fifthly, a computer program product or computer program is provided, the computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, causing the computer device to perform the steps of any of the methods described above.

[0068] The beneficial effects of the embodiments of this application are as follows:

[0069] In this embodiment, a tiered detection approach is used to perform attack detection on traffic information sent by network devices. This effectively enables in-depth detection of specific traffic, resulting in more accurate attack identification. Furthermore, by setting up multi-level detection methods, such as rule-based detection, transport layer feature detection, and application layer feature detection of traffic information, tiered processing of network traffic can be effectively achieved, significantly improving performance throughput. In addition, this application dynamically optimizes rules and models by reviewing historical judgment times, making the attack detection model more adaptable, effectively shortening the overall response time, improving the blocking success rate, and thus enhancing network security.

[0070] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0071] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0072] Figure 1 This is a schematic diagram illustrating an application scenario provided in the embodiments of this application;

[0073] Figure 2 An architecture diagram of an attack classification detection module provided in an embodiment of this application;

[0074] Figure 3 An architecture diagram of a rule and model update module provided in an embodiment of this application;

[0075] Figure 4 A flowchart illustrating a network attack detection method provided in an embodiment of this application;

[0076] Figure 5 This is a schematic diagram of a graded detection scenario provided in an embodiment of this application;

[0077] Figure 6 A schematic diagram of a rule and model update scenario provided in an embodiment of this application;

[0078] Figure 7 This is a schematic diagram of the network attack detection device provided in the embodiments of this application;

[0079] Figure 8 This is a schematic diagram of the composition structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0080] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.

[0081] To facilitate understanding of the technical solutions provided in the embodiments of this application, some key terms used in the embodiments of this application will be explained below:

[0082] (1) Side Prevent is a method of blocking attack traffic by monitoring the full traffic mirror in a bypass manner. Side Prevent works by listening to communication data in a bypass manner, then restoring the protocol, and blocking the attack based on the content. Side Prevent does not affect the speed of Internet access and does not require special settings from the user.

[0083] (2) An Intrusion Detection System (IDS) is a typical network security device that bypasses eavesdropping and blocks connections via TCP Reset. When an IDS detects an illegal connection, it sends a TCP RESET packet to both ends of the communication, thereby actively severing the connection. The design concept of this application's embodiments is briefly described below:

[0084] In the process of using the Internet, various network attacks are frequently encountered. In order to ensure network security and normal network access, effective network attack detection is essential.

[0085] Currently, the primary method for detecting network attacks is to use Intrusion Detection System (IDS) devices for monitoring. When the IDS detects an illegal connection, it sends a TCP RESET packet to both ends of the communication, thus proactively severing the connection. However, this method of detecting network attacks has delays in both response and attack, which may mean that by the time the RST reaches the session endpoint, the corresponding TCP session may have already ended, leading to session blocking failure. Furthermore, detection performance can easily become a bottleneck when dealing with large volumes of data packets.

[0086] Therefore, in order to better safeguard network security, timely and effective detection of network attacks is an urgent problem to be solved.

[0087] In view of the above problems, this application provides a network attack detection method. By employing a tiered detection approach, it performs attack detection on traffic information sent by network devices, effectively achieving deep detection of specific traffic and resulting in more accurate attack identification. Furthermore, by setting up multi-level detection methods, such as rule-based detection, transport layer feature detection, and application layer feature detection of traffic information, it effectively achieves tiered processing of network traffic, significantly improving performance throughput. In addition, this application dynamically optimizes the rules and models by reviewing historical judgment times, making the attack detection model more adaptable, effectively shortening the overall response time, increasing the blocking success rate, and thus improving network security.

[0088] The following is a brief introduction to the application scenarios to which the technical solutions of the embodiments of this application are applicable. It should be noted that the application scenarios described below are only for illustrating the embodiments of this application and are not intended to limit the scope. In specific implementation, the technical solutions provided by the embodiments of this application can be flexibly applied according to actual needs.

[0089] The technical solutions provided in this application can be applied to network attack detection scenarios for various network devices. For example, the network attack detection method provided in this application can be applied to scenarios oriented towards bypass blocking.

[0090] like Figure 1 The diagram shown is an application scenario provided by an embodiment of this application. In this scenario, a network IDS 100 and a target network device 200 may be included.

[0091] In one possible implementation, the application scenario may also include an intrusion detection system 300. In one possible implementation, the network IDS 100 may be a computer device with certain processing capabilities, such as a mobile phone, a personal computer (PC), or a server, which can be configured to execute any of the methods and devices provided in the embodiments of this application. Further examples will not be listed here.

[0092] Furthermore, in this embodiment of the application, the network IDS100 is equipped with an attack classification detection module 110 and a rule and model update module 120.

[0093] The attack classification detection module 110 is used to perform classification detection processing on the traffic information sent by the target network device.

[0094] The target network device 200 is the computer device to be detected by the network attack detection method provided in this application embodiment, such as a server, router, gateway device, etc. The server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms, but it is not limited to these.

[0095] The network IDS100 can obtain traffic information, such as log data, from the target network device 200, and implement network attack detection function for the target network device 200 based on the network attack detection method provided in this application embodiment.

[0096] It should be noted that, Figure 1 The examples shown are merely illustrative; in reality, the number of network IDS and target network devices is unlimited and is not specifically limited in this embodiment.

[0097] like Figure 2 The diagram shown is an architecture diagram of the attack classification detection module 110 provided in this application embodiment. The attack classification detection module 110 may include a first-layer judgment model 111, a second-layer judgment model 112, and a third-layer judgment model 113, thereby sequentially detecting and processing the traffic information.

[0098] Specifically, the first-layer judgment model 111 is used to perform attack judgment on the field rules of the traffic information;

[0099] The second-layer judgment model 112 is used to judge the attack on the transport layer characteristics of the traffic information;

[0100] The third-layer judgment model 113 is used to determine the attack on the application layer features of the traffic information.

[0101] like Figure 3 The diagram shown is an architecture diagram of the rule and model update module 120 provided in the embodiment of this application. The rule and model update module 120 may include a traffic information collection module 121 and a model rule update module 122.

[0102] The traffic information acquisition module 121 is used to acquire traffic information.

[0103] Specifically, the traffic information acquisition module 121 is used to acquire traffic information where the delay ratio exceeds the delay threshold.

[0104] The model rule update module 122 is used to dynamically optimize the attack detection module based on historical blocking information and update the attack judgment strategy of each layer of the judgment model.

[0105] It should be noted that Figure 2 or Figure 3 The components and structures shown in the functional module architecture diagram are merely exemplary and not restrictive. In real-world scenarios, other components and structures may be included as needed.

[0106] The network attack detection method provided by the exemplary embodiments of this application will be described below with reference to the accompanying drawings and the application scenarios described above. It should be noted that the application scenarios described above are only shown to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way in this respect.

[0107] See Figure 4 The diagram shown is a flowchart of the network attack detection method provided in this application embodiment. The example uses a network attack detection device as the executing entity. The specific implementation flow of this method is as follows:

[0108] Step 401: Obtain traffic information of the target network device to be detected.

[0109] Step 402: Perform hierarchical detection processing on the traffic information.

[0110] Specifically, when the network IDS performs hierarchical detection and processing on the traffic information, it can sequentially detect and process the traffic information through the first-layer judgment model, the second-layer judgment model, and the third-layer judgment model in the deployed attack detection module.

[0111] Step 403: When any detection level determines that an attack has occurred, stop the detection process at the next level and send a blocking link to the target network device.

[0112] As an example, in this embodiment of the application, when the network IDS performs hierarchical detection processing on the traffic information, the hierarchical detection scenario can be as follows: Figure 5 As shown.

[0113] The acquired traffic information is input into the first-layer judgment model. The field rules of the traffic information are obtained through the field rule processing module in the first-layer judgment model. Then, the field rules of the traffic information are judged through the rule judgment module in the first-layer judgment model.

[0114] For example, in one possible implementation, the field rules may include the following field information:

[0115] The traffic information includes fields such as domain name and URL. If an attack is detected, the subsequent process is stopped, and a blocking link is sent to the target network device; if no attack is detected, the traffic information is sent to the second-layer determination model.

[0116] Furthermore, after the second-layer determination model receives the traffic information, it obtains the transport layer features of the traffic information through the transport layer feature processing module in the second-layer determination model, and then judges the transport layer features of the traffic information through the transport layer determination module in the second-layer determination model.

[0117] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the traffic information is sent to the third-layer determination model.

[0118] Furthermore, after the third-layer determination model receives the traffic information, it obtains the application layer features of the traffic information through the application layer feature processing module in the third-layer determination model, and then judges the application layer features of the traffic information through the application layer determination module in the third-layer determination model.

[0119] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the network attack detection operation is terminated.

[0120] Furthermore, in order to make the network attack detection model of this application more accurate and effective in attack detection, this application embodiment also provides a method for model updating.

[0121] As an example, the rule and model update module in the network IDS described in this application embodiment can dynamically optimize the attack detection module based on historical blocking information and update the attack judgment strategy of each layer judgment model.

[0122] For example, such as Figure 6 As shown, the rule and model update module can collect the delay situation of the traffic information blocking processing. When it is determined that the delay ratio exceeds the delay threshold, the module adjusts the field rules of the first-layer judgment model and updates the second-layer and third-layer judgment models based on the collected delay situation.

[0123] For example, the transport layer features and application layer features of the traffic information are collected, the acquired transport layer features and application layer features are cropped, the second layer decision model is retrained and iterated based on the cropped transport layer features, and the third layer decision model is retrained and iterated based on the cropped application layer features.

[0124] For example, in practice, when this application embodiment performs model updates based on the rules and model update module, the specific implementation is as follows:

[0125] First, the attack classification detection module in the network IDS performs attack detection on the traffic information sent by the target network device.

[0126] After a period of time, assume that some of the attacks are identified by the rules of the first layer, another part of the attacks are identified by the transport layer feature determination model of the second layer, and the remaining part of the attacks are identified by the application layer feature determination model of the third layer, and assume that the blocking failure rate is 1.3%.

[0127] Assuming a preset blocking failure rate of 1%, the aforementioned blocking failure rate of 1.3% exceeds the preset failure rate. Therefore, it is necessary to adjust the rules and prune the features, initiate a retraining iteration based on the new feature model, and distribute and update the preset rule layer, transport layer decision model, and application information decision model.

[0128] After a period of time, the proportion of attacks significantly exceeding those detected by the first layer in the previous attack is identified by the rules of the first layer, the proportion of attacks significantly exceeding those detected by the second layer in the previous attack is identified by the transport layer feature judgment model of the second layer, and the proportion of attacks significantly exceeding those detected by the third layer in the previous attack is identified by the application layer feature judgment model of the third layer, and it is assumed that the blocking failure rate is 0.05%.

[0129] Since the blocking failure rate of 0.05% is less than the preset blocking failure rate of 1%, the update of the attack classification detection module is suspended, and the blocking data is continuously monitored.

[0130] This application employs a tiered detection approach to perform attack detection on traffic information sent by network devices. This effectively enables in-depth detection of specific traffic, resulting in more accurate attack identification. Furthermore, by setting up multi-level detection methods, such as rule-based detection, transport layer feature detection, and application layer feature detection of traffic information, it effectively achieves tiered processing of network traffic, significantly improving performance throughput. In addition, this application dynamically optimizes rules and models by reviewing historical judgment times, making the attack detection model more adaptable, effectively shortening the overall response time, increasing the blocking success rate, and thus improving network security.

[0131] Please see Figure 7 Based on the same inventive concept, this application also provides a network attack detection device 700, which includes:

[0132] The acquisition unit 701 is used to acquire traffic information of the target network device to be detected.

[0133] The hierarchical detection unit 702 is used to perform hierarchical detection processing on the traffic information;

[0134] The processing unit 703 is used to stop the next level of detection processing and send a blocking link to the target network device when any detection level determines that an attack has occurred.

[0135] In some optional implementations, the grading detection unit 702 is specifically used for:

[0136] The traffic information is detected and processed sequentially by the first-layer judgment model, the second-layer judgment model, and the third-layer judgment model in the deployed attack detection module.

[0137] The first-layer judgment model is used to determine attacks on the field rules of the traffic information.

[0138] The second-layer judgment model is used to determine the attack characteristics of the traffic information at the transport layer.

[0139] The third-layer judgment model is used to determine the attack characteristics of the traffic information at the application layer.

[0140] In some optional implementations, the grading detection unit 702 is specifically used for:

[0141] The field rules of the traffic information are obtained through the field rule processing module in the first-layer judgment model;

[0142] The rule determination module in the first-layer determination model determines the field rules of the traffic information.

[0143] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the traffic information is sent to the second-layer determination model.

[0144] In some optional implementations, the grading detection unit 702 is specifically used for:

[0145] The transport layer features of the traffic information are obtained through the transport layer feature processing module in the second-layer determination model.

[0146] The transport layer characteristics of the traffic information are determined by the transport layer determination module in the second-layer determination model.

[0147] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the traffic information is sent to the third-layer determination model.

[0148] In some optional implementations, the grading detection unit 702 is specifically used for:

[0149] The application layer features of the traffic information are obtained through the application layer feature processing module in the third-layer judgment model.

[0150] The application layer determination module in the third-layer determination model determines the application layer characteristics of the traffic information.

[0151] If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the network attack detection operation is terminated.

[0152] In some optional embodiments, the processing unit 703 is further configured to:

[0153] Based on historical blocking information, the attack detection module is dynamically optimized, and the attack judgment strategy of each layer judgment model is updated.

[0154] In some optional implementations, the processing unit 703 is specifically used for:

[0155] Adjust the field rules of the first-layer judgment model, as well as the transmission layer features and application layer features of the collected traffic information;

[0156] The acquired transport layer features and application layer features are then cropped.

[0157] The second-layer decision model is retrained and iterated based on the pruned transport layer features, and the third-layer decision model is retrained and iterated based on the pruned application layer features.

[0158] In some optional embodiments, the processing unit 703 is further configured to:

[0159] The delay in blocking the traffic information is collected;

[0160] It is determined that the percentage of delay exceeds the delay threshold.

[0161] Please see Figure 8 Based on the same technical concept, embodiments of this application also provide a computer device. In one embodiment, as shown in the figure, the computer device may include a memory 801, a communication module 803, and one or more processors 802.

[0162] The memory 801 is used to store computer programs executed by the processor 802. The memory 801 mainly includes a program storage area and a data storage area. The program storage area can store the operating system, and the data storage area can store various operation instruction sets, etc.

[0163] Memory 801 may be volatile memory, such as random-access memory (RAM); memory 801 may also be non-volatile memory, such as read-only memory, flash memory, hard disk drive (HDD), or solid-state drive (SSD); or memory 801 may be any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 801 may be a combination of the above-described memories.

[0164] The processor 802 may include one or more central processing units (CPUs) or digital processing units, etc. The processor 802 is used to implement the aforementioned network attack detection method when it calls the computer program stored in the memory 801.

[0165] The communication module 803 is used to communicate with message processing devices or other network devices.

[0166] This application embodiment does not limit the specific connection medium between the memory 801, communication module 803, and processor 802 described above. This application embodiment... Figure 8 The memory 801 and the processor 802 are connected via a bus 804, and the bus 804 is in Figure 8 The diagram uses thick lines to describe the connections between other components; these are for illustrative purposes only and should not be considered limiting. The 804 bus can be divided into address bus, data bus, control bus, etc. For ease of description, Figure 8 It is described using only a thick line, but does not indicate that there is only one bus or one type of bus.

[0167] The memory 801 stores a computer storage medium containing computer-executable instructions for implementing the network attack detection method of this application. The processor 802 executes the network attack detection methods of the above embodiments.

[0168] Based on the same inventive concept, embodiments of this application also provide a storage medium storing a computer program, which, when executed on a computer, causes the computer processor to perform the steps in the network attack detection methods according to various embodiments of this application described above.

[0169] In some possible implementations, various aspects of the network attack detection method provided in this application can also be implemented in the form of a program product, which includes program code. When the program product is run on a computer device, the program code is used to cause the computer device to perform the steps in the network attack detection method according to the various exemplary embodiments of this application described above. For example, the computer device can perform the steps of the various embodiments.

[0170] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0171] The program product of the embodiments of this application may employ a portable compact disc read-only memory (CD-ROM) and include program code, and may run on a computing device. However, the program product of this application is not limited thereto. In this application, the readable storage medium may be any tangible medium that contains or stores a program that may be used by or in conjunction with a command execution system, apparatus, or device.

[0172] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. This propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with a command execution system, apparatus, or device.

[0173] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0174] Program code for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0175] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0176] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0177] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0178] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0179] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A network attack detection method characterized by, The method includes: Obtain traffic information of the target network device to be detected; The traffic information is subjected to hierarchical detection and processing; When any detection level determines an attack, the next level of detection processing is stopped, and a link blocking message is sent to the target network device; the hierarchical detection processing of the traffic information includes: The traffic information is detected and processed sequentially by the first-layer judgment model, the second-layer judgment model, and the third-layer judgment model in the deployed attack detection module. The first-layer judgment model is used to determine attacks on the field rules of the traffic information. The second-layer judgment model is used to determine the attack characteristics of the traffic information at the transport layer. The third-layer judgment model is used to determine the attack characteristics of the traffic information at the application layer. The method further includes: Based on historical blocking information, the attack detection module is dynamically optimized, and the attack judgment strategy of each layer judgment model is updated. Specifically, based on historical blocking information, the attack detection module is dynamically optimized, and the attack determination strategies of each layer of the determination model are updated, including: Adjust the field rules of the first-layer judgment model, as well as the transmission layer features and application layer features of the collected traffic information; The acquired transport layer features and application layer features are then cropped. The second-layer decision model is retrained and iterated based on the pruned transport layer features, and the third-layer decision model is retrained and iterated based on the pruned application layer features.

2. The method of claim 1, wherein, The attack determination of the field rules of the traffic information is performed through the first-layer determination model, including: The field rules of the traffic information are obtained through the field rule processing module in the first-layer judgment model; The rule determination module in the first-layer determination model determines the field rules of the traffic information. If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the traffic information is sent to the second-layer determination model.

3. The method of claim 2, wherein, The attack determination of the transport layer characteristics of the traffic information is performed through the second-layer determination model, including: The transport layer features of the traffic information are obtained through the transport layer feature processing module in the second-layer determination model. The transport layer characteristics of the traffic information are determined by the transport layer determination module in the second-layer determination model. If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the traffic information is sent to the third-layer determination model.

4. The method as described in claim 3, characterized in that, The third-layer judgment model is used to determine the application layer characteristics of the traffic information for attack detection, including: The application layer features of the traffic information are obtained through the application layer feature processing module in the third-layer judgment model. The application layer determination module in the third-layer determination model determines the application layer characteristics of the traffic information. If an attack is detected, the subsequent process is stopped, and a link blocking message is sent to the target network device; if no attack is detected, the network attack detection operation is terminated.

5. The method as described in claim 1, characterized in that, Before dynamically optimizing the attack detection module based on historical blocking information and updating the attack determination strategy of each layer of the determination model, the method further includes: The delay in blocking the traffic information is collected; It is determined that the percentage of delay exceeds the delay threshold.

6. A network attack detection device, characterized in that, include: The acquisition unit is used to acquire traffic information of the target network device to be detected. A graded detection unit is used for graded detection and processing of the traffic information; The processing unit is used to stop the next level of detection processing and send a blocking link to the target network device when any detection level determines that an attack has occurred. The graded detection unit is specifically used for: The traffic information is detected and processed sequentially by the first-layer judgment model, the second-layer judgment model, and the third-layer judgment model in the deployed attack detection module. The first-layer judgment model is used to determine attacks on the field rules of the traffic information. The second-layer judgment model is used to determine the attack characteristics of the traffic information at the transport layer. The third-layer judgment model is used to determine the attack characteristics of the traffic information at the application layer. The processing unit is also used for: Adjust the field rules of the first-layer judgment model, as well as the transmission layer features and application layer features of the collected traffic information; The acquired transport layer features and application layer features are then cropped. The second-layer decision model is retrained and iterated based on the pruned transport layer features, and the third-layer decision model is retrained and iterated based on the pruned application layer features.

7. A computer device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the method as described in any one of claims 1 to 5 when executing the computer program.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When a computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 5.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Container cloud safety protection method and system constructed on basis of Kubernetes

    CN109347814A

  • Dual-mode intrusion detection device based on integrated machine learning algorithm

    CN110213287A