Network Event Detection Method, Device, Terminal Device, and Computer Storage Medium
By constructing a time sub-graph of event relationship attributes and performing graph representation learning, the accuracy and efficiency of network event detection in the prior art are solved, and efficient and accurate abnormal detection is achieved.
Patent Information
- Application Number
- CN202310178300.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-20
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2043-02-20
AI Technical Summary
The existing network event detection methods have defects in accuracy and efficiency, and cannot efficiently and accurately detect abnormal phenomena in network events.
By constructing a time subgraph of event relationship attributes, using the preset five-tuple attributes and edge relationship types, the target network event is graphically represented, feature representation data is obtained, and detection is performed to obtain detection results.
It improves the detection performance of network events, realizes fast and accurate abnormal detection, and avoids the poor efficiency of existing detection models.
Smart Images

Figure CN116170221B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of network security, and in particular, to a network event detection method, device, terminal device, and computer storage medium. Background Art
[0002] With the rapid development of the Internet, network security issues have become increasingly prominent, and users' network facilities and network data have become the key targets of hacker attacks. Therefore, users have put forward higher requirements for network anomaly detection means.
[0003] Currently, most existing network event detection methods are divided into the following two detection models. The first detection model takes the attributes in the event, including processes, files, users, etc. as nodes, constructs a heterogeneous graph that can represent event entities, and calculates the possibility of the occurrence of event entities on this heterogeneous graph to determine anomalies. The other detection model directly takes the logs representing events as nodes and constructs a heterogeneous graph based on the attribute correlation between the logs. However, both of these detection models have great defects. The former only focuses on the attribute characteristics of the network event itself, that is, the accuracy of detecting network event anomalies is poor; while the latter, although considering the structural characteristics between events, due to its complex edge relationships, the generated heterogeneous graph is too dense, thus weakening the key role of the structural characteristics, and further resulting in poor efficiency in detecting network event anomalies.
[0004] In summary, how to efficiently and accurately detect anomalies in network events is a technical problem that needs to be solved urgently at present. Summary of the Invention
[0005] The main purpose of this application is to provide a network event detection method, device, terminal device, and computer storage medium, aiming to improve the performance of detecting network event anomalies.
[0006] To achieve the above object, this application provides a network event detection method, and the network event detection method includes:
[0007] Construct an event relationship attribute time subgraph according to the original log data in multiple original network events;
[0008] Search for the target log data in the target network event from the event relationship attribute time subgraph according to the preset five-tuple attributes, and obtain the target graph node corresponding to the target network event, where the target network event refers to any one of the multiple original network events;
[0009] Perform graph representation learning on the target graph node according to the preset edge relationship type to obtain the feature representation data of the target graph node;
[0010] Detect the target network event according to the feature representation data to obtain the detection result of the target network event.
[0011] Optionally, the step of constructing an event relationship attribute time subgraph based on the raw log data in multiple original network events includes:
[0012] Perform identification processing on the raw log data in multiple original network events according to the five-tuple attribute to obtain the original graph nodes corresponding to each original network event;
[0013] Obtain multiple remaining attributes other than the five-tuple attribute;
[0014] Calculate each remaining attribute according to a preset information gain algorithm to obtain the information gain value corresponding to each remaining attribute;
[0015] Arrange the multiple information gain values in descending order to obtain a gain arrangement table;
[0016] Extract the node attributes corresponding to multiple original graph nodes from the gain arrangement table according to the descending order of the gain arrangement table and a preset extraction quantity;
[0017] Construct an event relationship attribute time subgraph according to the multiple node attributes extracted.
[0018] Optionally, the step of constructing an event relationship attribute time subgraph according to the multiple node attributes extracted includes:
[0019] Connect the original graph nodes with the same node attributes according to the edge relationship type to obtain multiple connected nodes;
[0020] Determine the edge relationships corresponding to multiple connected nodes, and construct an event relationship attribute time subgraph according to the multiple edge relationships and the timestamp in the five-tuple attribute.
[0021] Optionally, the multiple connected nodes at least include: a first connected node, a second connected node, and a third connected node. The number of the first connected node, the second connected node, and the third connected node is multiple. The step of connecting the original graph nodes with the same node attributes according to the edge relationship type to obtain multiple connected nodes includes:
[0022] Obtain the first node attribute, the second node attribute, and the third node attribute in the edge relationship type;
[0023] Connect the original graph nodes with the same node attribute as the first node attribute to obtain the first connected node;
[0024] Connect the original graph nodes with the same node attributes as the second node attributes to obtain second connection nodes;
[0025] Connect the original graph nodes with the same node attributes as the third node attributes to obtain third connection nodes.
[0026] Optionally, the step of constructing an event relationship attribute time subgraph according to multiple edge relationships and timestamps in the five-tuple attributes includes:
[0027] Construct an event relationship attribute graph according to multiple edge relationships;
[0028] Partition the event relationship attribute graph according to the timestamp, and use the partitioned event relationship attribute graph as the event relationship attribute time subgraph.
[0029] Optionally, the step of performing graph representation learning on the target graph nodes according to a preset edge relationship type to obtain feature representation data of the target graph nodes includes:
[0030] Find the target edge relationship corresponding to the target graph node from the event relationship attribute time subgraph according to the edge relationship type, and determine the target node attribute corresponding to the target graph node;
[0031] Calculate the found target edge relationship and target node attribute according to a preset specific algorithm to obtain a set of neighbor graph nodes adjacent to the target graph node;
[0032] Obtain the set attribute corresponding to the set of neighbor graph nodes, and aggregate the target node attribute, the set attribute, and the target edge relationship according to a preset aggregation function to obtain the feature representation data of the target graph node.
[0033] Optionally, the step of detecting the target network event according to the feature representation data to obtain the detection result of the target network event includes:
[0034] Obtain the test data of the target network event according to the feature representation data and a preset activation function;
[0035] Judge whether the test data is within a preset network normal threshold range;
[0036] If the test data is within the network normal threshold range, determine that the detection result is normal network communication;
[0037] If the test data is not within the network normal threshold range, determine that the detection result is abnormal network communication, and obtain the network attack type corresponding to the detection result.
[0038] In addition, to achieve the above object, the present application further provides a network event detection device, and the network event detection device of the present application includes:
[0039] A construction module, configured to construct an event relationship attribute time sub-graph according to the original log data in a plurality of original network events;
[0040] A search module, configured to search for the target log data in the target network event from the event relationship attribute time sub-graph according to a preset five-tuple attribute, so as to obtain a target graph node corresponding to the target network event, where the target network event refers to any one of the plurality of original network events;
[0041] A learning module, configured to perform graph representation learning on the target graph node according to a preset edge relationship type, so as to obtain feature representation data of the target graph node;
[0042] A detection module, configured to detect the target network event according to the feature representation data, so as to obtain a detection result of the target network event.
[0043] Each functional module of the network event detection device of the present application implements the steps of the network event detection method of the present application as described above when running.
[0044] In addition, to achieve the above object, the present application further provides a terminal device, and the terminal device includes a memory, a processor, and a network event detection program stored on the memory and executable on the processor. When the network event detection program is executed by the processor, the steps of the above network event detection method are implemented.
[0045] In addition, to achieve the above object, the present application further provides a computer storage medium, and a network event detection program is stored on the computer storage medium. When the network event detection program is executed by a processor, the steps of the above network event detection method are implemented.
[0046] In the present application, first, an event relationship attribute time sub-graph is constructed according to the original log data in a plurality of original network events; then, the target log data in the target network event is searched from the event relationship attribute time sub-graph according to a preset five-tuple attribute, so as to obtain a target graph node corresponding to the target log data, where the target network event refers to any one of the plurality of original network events; then, graph representation learning is performed on the target graph node according to a preset edge relationship type, so as to obtain feature representation data of the target graph node; and then, the target network event is detected according to the feature representation data, so as to obtain a detection result of the target network event.
[0047] Different from the traditional network event detection method, the present application constructs an event relationship attribute time subgraph, and according to the preset five-tuple attribute, the target graph node corresponding to the target log data can be quickly found in the event relationship attribute time subgraph. After determining the target graph node, the target graph node is learned by graph representation according to the preset edge relationship type, so that the feature representation data of the target graph node can be accurately obtained, and then the target network event is detected in a targeted manner according to the feature representation data, and the detection result of the target network event can be obtained quickly and accurately, which effectively avoids the technical problem of poor detection efficiency of the existing detection model for network event detection, and effectively improves the performance of network event detection through the constructed event relationship attribute time subgraph. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 It is a flowchart of the first embodiment of the network event detection method of the present application;
[0049] Figure 2 It is a structural diagram of a network event detection device involved in an embodiment of the present application;
[0050] Figure 3 This is a schematic diagram of the structure of a terminal device involved in the embodiment of the present application;
[0051] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0052] The present application embodiment provides a network event detection method, referring to Figure 1 As shown, Figure 1 It is a flowchart of the first embodiment of the network event detection method of the present application.
[0053] Here, exemplary embodiments are described in detail, and examples thereof are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application.
[0054] In this embodiment, the network event detection method of the present application is applied to a terminal device for detecting network events, and is specifically executed by a control center of the terminal device.
[0055] The network event detection method of the present application includes:
[0056] Step S10: constructing an event relationship attribute time subgraph according to original log data in a plurality of original network events.
[0057] In this embodiment, the control center simultaneously performs identification processing on the original log data in multiple original network events according to the preset five-tuple attributes, and obtains the original graph nodes corresponding to each of the multiple original network events; while determining the multiple original graph nodes, the control center obtains multiple remaining attributes other than the preset five-tuple attributes, and calculates the information gain values corresponding to each of the remaining attributes and the entropy corresponding to each of the remaining attributes respectively according to the preset information gain algorithm; after determining the multiple information gain values, the control center sorts the multiple information gain values in descending order to obtain a gain ranking table, and then extracts the node attributes corresponding to each of the multiple original graph nodes from the gain ranking table according to the descending order of the gain ranking table and the preset extraction quantity; and connects the original graph nodes with the same node attributes according to the preset edge relationship type to obtain multiple connected nodes; then the control center can determine the edge relationships corresponding to each of the multiple connected nodes, and construct an event relationship attribute time subgraph according to the multiple edge relationships and the timestamp in the five-tuple attributes.
[0058] It should be noted that the preset five-tuple attributes include: source IP address, source port number, destination IP address, destination port number, and timestamp. That is, according to the above five-tuple attributes, the event attributes corresponding to each original network event can be identified, and this event attribute is used as the original graph node corresponding to the original network event.
[0059] In this embodiment, the present application fully considers the abnormal characteristics of network events in reality. By presetting the timestamp, that is, taking the time attribute as the feature of the network event, abnormal conditions can be detected more effectively.
[0060] Step S20: Search for the target log data in the target network event according to the preset five-tuple attributes in the event relationship attribute time subgraph to obtain the target graph node corresponding to the target network event, where the target network event refers to any one of the multiple original network events.
[0061] In this embodiment, the control center searches for the target log data in the target network event according to the preset five-tuple attributes in the event relationship attribute time subgraph to obtain the target graph node corresponding to the target network event.
[0062] It should be noted that the target network event refers to any one of the multiple original network events
[0063] Step S30: Perform graph representation learning on the target graph node according to the preset edge relationship type to obtain the feature representation data of the target graph node.
[0064] In this embodiment, after the construction of the event relationship attribute time subgraph is completed, the control center searches for the target edge relationship corresponding to the target graph node from the event relationship attribute time subgraph according to the preset edge relationship type, and determines the target node attribute corresponding to the target graph node; then, in the event relationship attribute time subgraph, the obtained target edge relationship and target node attribute are calculated according to a preset specific algorithm to obtain a set of neighbor graph nodes adjacent to the target graph node; after the set of neighbor graph nodes is determined, the control center will obtain the set attribute corresponding to the set of neighbor graph nodes, and aggregate the target node attribute, the set attribute, and the target edge relationship according to a preset aggregation function to obtain the feature representation data of the target graph node.
[0065] In this embodiment, graph representation learning is performed on the target graph node according to the preset edge relationship type to accurately obtain the feature representation data of the target graph node. This feature representation data not only aggregates the node attributes of the target graph node and its neighbor graph nodes, but also can jointly aggregate the edge attributes that can represent the relationship between nodes, fully considering the mutual dependence relationship between the nodes representing events, and improving the detection performance.
[0066] Step S40: Detect the target network event according to the feature representation data to obtain the detection result of the target network event.
[0067] In this embodiment, the control center can obtain the test data of the target network event according to the feature representation data and a preset activation function; after the test data is determined, the control center can then determine whether the test data is within the preset network normal threshold range; if the test data is within the network normal threshold range, it is determined that the detection result is normal network communication; if the test data is not within the network normal threshold range, it is determined that the detection result is abnormal network communication, and the network attack type corresponding to the detection result is obtained.
[0068] In this embodiment, the present application first obtains the test data of the target network event according to the feature representation data and a preset activation function, and then performs targeted detection on the target network event according to the test data, effectively improving the detection accuracy.
[0069] Further, based on the first embodiment of the network event detection of the present application, a second embodiment of the network event detection of the present application is proposed.
[0070] Further, in some feasible embodiments, the above step S10: Construct an event relationship attribute time subgraph according to the original log data in multiple original network events may further include the following implementation steps:
[0071] Step S101: Identify the original log data in multiple original network events according to the quintuple attributes, and obtain the original graph nodes corresponding to each of the original network events.
[0072] In this embodiment, the control center identifies the original log data in multiple original network events according to the quintuple attributes, and obtains the original graph nodes corresponding to each of the original network events.
[0073] In a specific embodiment, the control center searches the original log data in the original network event A according to the preset quintuple attributes, that is, extracts the source IP address, source port number, destination IP address, destination port number, and timestamp in the original log data A, and then determines the event attribute A corresponding to the original network event A according to the source IP address, source port number, destination IP address, destination port number, and timestamp extracted from the original log data A, and uses this event attribute A as the graph node of the original network event A.
[0074] Step S102: Obtain multiple remaining attributes other than the quintuple attributes.
[0075] In this embodiment, the control center can obtain multiple remaining attributes other than the quintuple attributes.
[0076] It should be noted that the remaining attributes refer to other attributes other than the quintuple attributes, and are used to identify the node attributes of the graph nodes.
[0077] Step S103: Calculate each of the remaining attributes according to a preset information gain algorithm, and obtain the information gain value corresponding to each of the remaining attributes.
[0078] In this embodiment, the control center calculates each of the remaining attributes according to the first calculation formula in the preset information gain algorithm to obtain the entropy corresponding to each of the remaining attributes. After determining the entropy corresponding to each of the remaining attributes, the control center calculates the entropy corresponding to each of the remaining attributes according to the second calculation formula in the preset information gain algorithm, and can obtain the information gain value corresponding to each of the remaining attributes.
[0079] It should be noted that the first calculation formula can be understood as being used to calculate the entropy of each remaining attribute, and the expression of the first calculation formula is as shown in Equation 1 below:
[0080]
[0081] Among them, c represents the number of classification category values, p iRepresents the number of samples in category i. Additionally, the classification category value can be understood as a binary classification, namely normal classification of network events and abnormal classification of network events. Moreover, in the abnormal classification of network events, multiple network attack types are further subdivided, such as denial-of-service attack events, backdoor attack events, vulnerability attack events, network scanning and eavesdropping events, phishing events, interference events, and other network attack events.
[0082] In addition, it should be noted that the second calculation formula can be understood as being used to calculate the information gain value of each remaining attribute based on the entropy of each remaining attribute, and the expression of the second calculation formula is as shown in Equation 2 below:
[0083]
[0084] Where S is the sample of the remaining attributes, A represents the remaining attributes, v represents the possible value of the remaining attribute A, Value(A) represents a series of possible values of the remaining attribute A, |S v | represents the sample with the value of v, |S| represents the number of samples of all remaining attributes, and Entropy(S v ) represents the entropy of the sample with the value of v.
[0085] Step S104: Arrange the multiple information gain values in descending order to obtain a gain arrangement table;
[0086] In this embodiment, the control center arranges the information gain values corresponding to the multiple remaining attributes in descending order, that is, sorts the multiple information gain values from largest to smallest to obtain a gain arrangement table.
[0087] It should be noted that the gain arrangement table can be understood as multiple sorted information gain values.
[0088] Step S105: Extract the node attributes corresponding to the multiple original graph nodes from the gain arrangement table according to the descending order sequence of the gain arrangement table and a preset extraction quantity;
[0089] In this embodiment, the control center extracts the node attributes corresponding to the multiple original graph nodes from the gain arrangement table according to the descending order sequence of the gain arrangement table and a preset extraction quantity.
[0090] It should be noted that the extraction quantity can be customized according to the user's needs and is not limited in this application.
[0091] In a specific embodiment, assume there is an original graph node A and the preset extraction quantity is 10; the control center can extract 10 most representative remaining attributes from the gain arrangement table according to the descending order sequence of the gain arrangement table and use these 10 most representative remaining attributes as the node attributes corresponding to the original graph node A.
[0092] Step S106: Construct an event relationship attribute time subgraph based on the multiple extracted node attributes.
[0093] In this embodiment, the control center connects the original graph nodes with the same node attributes according to the preset edge relationship type to obtain multiple connected nodes, then determines the edge relationships corresponding to the multiple connected nodes respectively, and constructs an event relationship attribute time subgraph based on the multiple edge relationships and the timestamps in the five-tuple attributes.
[0094] It should be noted that a connected node can be understood as the intersection point where the original graph node A and the original graph node B are connected when the node attributes of the original graph node A and the original graph node B are the same.
[0095] Further, in some other feasible embodiments, the above Step S106: Construct an event relationship attribute time subgraph based on the multiple extracted node attributes may further include the following implementation steps:
[0096] Step S1061: Connect the original graph nodes with the same node attributes according to the edge relationship type to obtain multiple connected nodes;
[0097] In this embodiment, the control center connects the original graph nodes with the same node attributes according to the edge relationship type to obtain multiple connected nodes.
[0098] Step S1062: Determine the edge relationships corresponding to the multiple connected nodes respectively, and construct an event relationship attribute time subgraph based on the multiple edge relationships and the timestamps in the five-tuple attributes.
[0099] In this embodiment, the control center determines the edge relationships corresponding to the multiple connected nodes respectively, and constructs an event relationship attribute time subgraph based on the multiple edge relationships and the timestamps in the five-tuple attributes.
[0100] Further, in some feasible embodiments, the multiple connected nodes at least include: a first connected node, a second connected node, and a third connected node, and the numbers of the first connected node, the second connected node, and the third connected node are all multiple. The above Step S1061: Connect the original graph nodes with the same node attributes according to the edge relationship type to obtain multiple connected nodes may further include the following implementation steps:
[0101] Step S10611: Obtain the first node attribute, the second node attribute, and the third node attribute in the edge relationship type;
[0102] In this embodiment, the control center obtains the first node attribute, the second node attribute, and the third node attribute in the preset edge relationship type.
[0103] It should be noted that the first node attribute, i.e., the first edge relationship, may specifically include: at least two graph nodes having the same source IP address, source port number, destination IP address, and destination port number.
[0104] The second node attribute, i.e., the second edge relationship, may specifically include: at least two graph nodes having the same source IP address and source port number.
[0105] The third node attribute, i.e., the third edge relationship, may specifically include: at least two graph nodes having the same destination IP address and destination port number.
[0106] In addition, it should be noted that the weight of the first node attribute is greater than the weight of the second node attribute, and the weight of the second node attribute is greater than the weight of the third node attribute.
[0107] Step S10612: Connect the original graph nodes with the same node attributes as the first node attribute to obtain a first connected node;
[0108] In this embodiment, the control center connects the original graph nodes with the same node attributes as the first node attribute to obtain a first connected node.
[0109] Step S10613: Connect the original graph nodes with the same node attributes as the second node attribute to obtain a second connected node;
[0110] In this embodiment, if multiple original graph nodes with the same first node attribute are not found in the original graph node set, or after determining multiple first connected nodes, the control center will connect the original graph nodes with the same node attributes as the second node attribute to obtain a second connected node.
[0111] Step S10614: Connect the original graph nodes with the same node attributes as the third node attribute to obtain a third connected node.
[0112] In this embodiment, if multiple original graph nodes with the same second node attribute are not found in the original graph node set, or after determining multiple second connected nodes, the control center will connect the original graph nodes with the same node attributes as the third node attribute to obtain a third connected node.
[0113] Furthermore, in some feasible embodiments, the above step S1062: Construct an event relationship attribute time subgraph according to the multiple edge relationships and the timestamp in the five-tuple attribute may further include the following implementation steps:
[0114] Step S10621: Construct an event relationship attribute graph according to the multiple edge relationships;
[0115] In this embodiment, the control center trains and learns multiple edge relationships to establish an event relationship attribute graph.
[0116] Step S10622: Divide the event relationship attribute graph according to the time stamp, and use the divided event relationship attribute graph as an event relationship attribute time sub-graph.
[0117] In this embodiment, the control center divides the event relationship attribute graph according to different time stamps to obtain multiple time sub-graphs of event relationship attributes (i.e., the divided event relationship attribute graph), and uses the divided event relationship attribute graph as an event relationship attribute time sub-graph.
[0118] It should be noted that there are multiple time stamps, and each time stamp is different from other time stamps, that is, the values corresponding to each time stamp are different.
[0119] Further, in some other feasible embodiments, the above step S30: performing graph representation learning on the target graph node according to a preset edge relationship type to obtain the feature representation data of the target graph node may further include the following implementation steps:
[0120] Step S301: Search for the target edge relationship corresponding to the target graph node from the event relationship attribute time sub-graph according to the edge relationship type, and determine the target node attribute corresponding to the target graph node.
[0121] In this embodiment, the control center searches for the target edge relationship corresponding to the target graph node from the event relationship attribute time sub-graph according to the edge relationship type, and determines the target node attribute corresponding to the target graph node.
[0122] Step S302: Calculate the found target edge relationship and the target node attribute according to a preset specific algorithm to obtain a set of neighbor graph nodes adjacent to the target graph node.
[0123] In this embodiment, after determining that the target edge relationship, the target node attribute, multiple original graph nodes, and the node attributes corresponding to each original graph node are input values in a preset specific algorithm, the control center performs positive and negative sampling on each original graph node in the event relationship attribute time sub-graph to obtain a set of neighbor graph nodes adjacent to the target graph node.
[0124] It should be noted that positive and negative sampling includes positive sampling and negative sampling. Among them, positive sampling means classifying those with a high degree of closeness between the target node and the original node into one category; negative sampling means classifying those with a low degree of closeness between the target node and the original node into one category.
[0125] Step S303: Obtain the set attributes corresponding to the neighbor graph node set, and aggregate the target node attributes, the set attributes, and the target edge relationships according to a preset aggregation function to obtain the feature representation data of the target graph node.
[0126] In this embodiment, the control center obtains the set attributes corresponding to the neighbor graph node set, and aggregates the target node attributes, the set attributes, and the target edge relationships according to a preset aggregation function to obtain the feature representation data of the target graph node.
[0127] Further, in some feasible embodiments, the above step S40: Detect the target network event according to the feature representation data to obtain the detection result of the target network event, and further includes the following implementation steps:
[0128] Step S401: Obtain the test data of the target network event according to the feature representation data and a preset activation function.
[0129] In this embodiment, the control center obtains the test data of the target network event according to the feature representation data and a preset activation function.
[0130] Step S402: Determine whether the test data is within a preset network normal threshold range.
[0131] In this embodiment, the control center determines whether the test data is within a preset network normal threshold range.
[0132] Step S403: If the test data is within the network normal threshold range, determine that the detection result is normal network communication.
[0133] In this embodiment, if the test data is within the network normal threshold range, the control center can determine that the detection result is normal network communication.
[0134] Step S404: If the test data is not within the network normal threshold range, determine that the detection result is abnormal network communication, and obtain the network attack type corresponding to the detection result.
[0135] In this embodiment, if the test data is not within the network normal threshold range, the control center can determine that the detection result is abnormal network communication, and obtain the network attack type corresponding to the detection result.
[0136] In summary, the present application constructs different temporal subgraphs representing event relationship attributes (i.e., event relationship attribute temporal subgraphs), enabling the features of network events to be better aggregated, and then detecting target network events in a targeted manner. Moreover, the event relationship attribute temporal subgraph of the present application can be trained using a smaller training set (multiple original network events), thereby effectively improving the efficiency and accuracy of detection.
[0137] In addition, the present application also provides a network event detection device. Please refer to Figure 2 , Figure 2 which is a schematic structural diagram of the network event detection device involved in the solution of the embodiment of the present application.
[0138] The network event detection device of the present application includes:
[0139] A construction module H01, configured to construct an event relationship attribute temporal subgraph according to the original log data in multiple original network events;
[0140] A search module H02, configured to search for the target log data in the target network event according to a preset five-tuple attribute in the event relationship attribute temporal subgraph, to obtain a target graph node corresponding to the target network event, where the target network event refers to any one of the multiple original network events;
[0141] A learning module H03, configured to perform graph representation learning on the target graph node according to a preset edge relationship type, to obtain the feature representation data of the target graph node;
[0142] A detection module H04, configured to detect the target network event according to the feature representation data, to obtain the detection result of the target network event.
[0143] Optionally, the construction module H01 may further include:
[0144] An identification processing unit, configured to perform identification processing on the original log data in multiple original network events according to the five-tuple attribute, to obtain the original graph nodes corresponding to the respective original network events;
[0145] A first acquisition unit, configured to acquire multiple remaining attributes other than the five-tuple attribute;
[0146] A first calculation unit, configured to calculate the respective remaining attributes according to a preset information gain algorithm, to obtain the information gain values corresponding to the respective remaining attributes;
[0147] An arrangement unit, configured to perform a descending order arrangement on multiple information gain values, to obtain a gain arrangement table;
[0148] An extraction unit, configured to extract the node attributes corresponding to each of the multiple original graph nodes from the gain arrangement table according to the descending order of the gain arrangement table and a preset extraction quantity;
[0149] Construct an event relationship attribute time sub-graph based on the multiple node attributes extracted.
[0150] Optionally, the construction module H01 may further include:
[0151] A first connection unit, configured to connect the original graph nodes with the same node attributes according to the edge relationship type to obtain multiple connected nodes;
[0152] A first construction unit, configured to determine the edge relationships corresponding to each of the multiple connected nodes, and construct an event relationship attribute time sub-graph based on the multiple edge relationships and the timestamps in the five-tuple attributes.
[0153] Optionally, the construction module H01 may further include:
[0154] A second acquisition unit, configured to acquire a first node attribute, a second node attribute, and a third node attribute in the edge relationship type;
[0155] A second connection unit, configured to connect the original graph nodes with the same node attributes as the first node attribute to obtain first connected nodes;
[0156] A third connection unit, configured to connect the original graph nodes with the same node attributes as the second node attribute to obtain second connected nodes;
[0157] A fourth connection unit, configured to connect the original graph nodes with the same node attributes as the third node attribute to obtain third connected nodes.
[0158] Optionally, the construction module H01 may further include:
[0159] A second construction unit, configured to construct an event relationship attribute graph based on the multiple edge relationships;
[0160] A partitioning unit, configured to partition the event relationship attribute graph according to the timestamp, and use the partitioned event relationship attribute graph as an event relationship attribute time sub-graph.
[0161] Optionally, the learning module H03 may further include:
[0162] A relationship determination unit, configured to find the target edge relationship corresponding to the target graph node from the event relationship attribute time sub-graph according to the edge relationship type, and determine the target node attribute corresponding to the target graph node;
[0163] A second computing unit, configured to calculate the found target edge relationship and the target node attributes according to a preset specific algorithm to obtain a set of neighbor graph nodes adjacent to the target graph node;
[0164] An aggregation unit, configured to obtain set attributes corresponding to the set of neighbor graph nodes, and aggregate the target node attributes, the set attributes, and the target edge relationship according to a preset aggregation function to obtain feature representation data of the target graph node.
[0165] Optionally, the detection module H04 may further include:
[0166] An activation unit, configured to obtain test data of the target network event according to the feature representation data and a preset activation function;
[0167] A judgment unit, configured to judge whether the test data is within a preset network normal threshold range;
[0168] A normal communication unit, configured to determine that the detection result is normal network communication if the test data is within the network normal threshold range;
[0169] An abnormal communication unit, configured to determine that the detection result is abnormal network communication if the test data is not within the network normal threshold range, and obtain a network attack type corresponding to the detection result.
[0170] Each functional module of the network event detection device of the present application implements the steps of the network event detection method of the present application as described above when running.
[0171] In addition, the present application further provides a terminal device. Please refer to Figure 3 , Figure 3 which is a schematic structural diagram of the terminal device involved in the solution of the embodiment of the present application. The terminal device in the embodiment of the present application may specifically be a device for locally running network event detection.
[0172] As Figure 3 shown, the terminal device in the embodiment of the present application may include: a processor 1001, such as a CPU, a communication bus 1002, a user interface 1003, a network interface 1004, a memory 1005, and a sensing unit 1006. Among them, the communication bus 1002 is used to implement connection communication between these components. The user interface 1003 may include a display screen (Display) and an input unit such as a keyboard (Keyboard). Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a Wi-Fi interface).
[0173] The memory 1005 is provided on the terminal device body. A program is stored on the memory 1005, and when the program is executed by the processor 1001, corresponding operations are implemented. The memory 1005 is also used to store parameters for the terminal device to use. The memory 1005 can be a high-speed RAM memory or a stable memory (non-volatile memory), such as a disk memory. Optionally, the memory 1005 can also be a storage device independent of the aforementioned processor 1001.
[0174] Those skilled in the art can understand that Figure 3 the structure of the terminal device shown in
[0175] does not constitute a limitation on the terminal device, and may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements. Figure 3 As shown in
[0176] the memory 1005, as a storage medium, may include an operating system, a network communication module, a user interface module, and a network event detection program for the terminal device. Figure 3 In the terminal device shown in
[0177] the processor 1001 can be used to call the network event detection program stored in the memory 1005 and perform the following operations.
[0178] Construct an event relationship attribute time sub-graph according to the original log data in multiple original network events;
[0179] Search for the target log data in the target network event according to the preset five-tuple attribute from the event relationship attribute time sub-graph to obtain the target graph node corresponding to the target network event, where the target network event refers to any one of the multiple original network events;
[0180] Perform graph representation learning on the target graph node according to the preset edge relationship type to obtain the feature representation data of the target graph node;
[0181] According to the feature representation data, detect the target network event to obtain the detection result of the target network event.
[0182] Further, the operation of constructing an event relationship attribute time sub-graph according to the original log data in multiple original network events includes:
[0183] Perform identification processing on the original log data in multiple original network events according to the five-tuple attribute to obtain the original graph nodes corresponding to each of the original network events;
[0184] Calculate each of the remaining attributes according to a preset information gain algorithm to obtain the information gain value corresponding to each of the remaining attributes;
[0185] Arrange the multiple information gain values in descending order to obtain a gain arrangement table;
[0186] Extract the node attributes corresponding to each of the multiple original graph nodes from the gain arrangement table according to the descending order of the gain arrangement table and a preset extraction quantity;
[0187] Construct an event relationship attribute time subgraph based on the multiple node attributes extracted;
[0188] Further, the operation of constructing an event relationship attribute time subgraph based on the multiple node attributes extracted includes:
[0189] Connect the original graph nodes with the same node attributes according to the edge relationship type to obtain multiple connected nodes;
[0190] Determine the edge relationships corresponding to the multiple connected nodes, and construct an event relationship attribute time subgraph based on the multiple edge relationships and the timestamps in the five-tuple attributes.
[0191] Further, the multiple connected nodes at least include: a first connected node, a second connected node, and a third connected node. The number of the first connected node, the second connected node, and the third connected node is multiple. The operation of connecting the original graph nodes with the same node attributes according to the edge relationship type to obtain multiple connected nodes includes:
[0192] Obtain a first node attribute, a second node attribute, and a third node attribute in the edge relationship type;
[0193] Connect the original graph nodes with the same node attributes as the first node attribute to obtain a first connected node;
[0194] Connect the original graph nodes with the same node attributes as the second node attribute to obtain a second connected node;
[0195] Connect the original graph nodes with the same node attributes as the third node attribute to obtain a third connected node.
[0196] Further, the operation of constructing an event relationship attribute time subgraph based on the multiple edge relationships and the timestamps in the five-tuple attributes includes:
[0197] Construct an event relationship attribute graph based on the multiple edge relationships;
[0198] Partition the event relationship attribute graph according to the time stamp, and use the partitioned event relationship attribute graph as the event relationship attribute time sub-graph.
[0199] Further, the operation of performing graph representation learning on the target graph nodes according to a preset edge relationship type to obtain the feature representation data of the target graph nodes includes:
[0200] Find the target edge relationship corresponding to the target graph node from the event relationship attribute time sub-graph according to the edge relationship type, and determine the target node attribute corresponding to the target graph node;
[0201] Calculate the found target edge relationship and the target node attribute according to a preset specific algorithm to obtain a set of neighbor graph nodes adjacent to the target graph node;
[0202] Obtain the set attribute corresponding to the set of neighbor graph nodes, and aggregate the target node attribute, the set attribute, and the target edge relationship according to a preset aggregation function to obtain the feature representation data of the target graph node.
[0203] Further, the operation of detecting the target network event according to the feature representation data to obtain the detection result of the target network event includes:
[0204] Obtain the test data of the target network event according to the feature representation data and a preset activation function;
[0205] Judge whether the test data is within a preset network normal threshold range;
[0206] If the test data is within the network normal threshold range, determine that the detection result is normal network communication;
[0207] If the test data is not within the network normal threshold range, determine that the detection result is abnormal network communication, and obtain the network attack type corresponding to the detection result.
[0208] It should be noted that in this article, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or system. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or system including the element.
[0209] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.
[0210] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a computer storage medium as described above (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present application.
[0211] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present application.
Claims
1. A network event detection method, characterized in that, the network event detection method includes: constructing an event relationship attribute time subgraph according to the original log data in multiple original network events; searching for the target log data in the target network event from the event relationship attribute time subgraph according to a preset five-tuple attribute to obtain a target graph node corresponding to the target network event, where the target network event refers to any one of the multiple original network events, and the five-tuple attribute includes source IP address, source port number, target IP address, target port number, and timestamp; performing graph representation learning on the target graph node according to a preset edge relationship type to obtain feature representation data of the target graph node; detecting the target network event according to the feature representation data to obtain a detection result of the target network event; the step of constructing an event relationship attribute time subgraph according to the original log data in multiple original network events includes: performing identification processing on the original log data in multiple original network events according to the five-tuple attribute to obtain original graph nodes corresponding to each original network event; obtaining multiple remaining attributes except the five-tuple attribute; calculating each remaining attribute according to a preset information gain algorithm to obtain an information gain value corresponding to each remaining attribute; performing a descending order arrangement on the multiple information gain values to obtain a gain arrangement table; extracting node attributes corresponding to each of the multiple original graph nodes from the gain arrangement table according to the descending order sequence of the gain arrangement table and a preset extraction quantity; constructing an event relationship attribute time subgraph according to the multiple extracted node attributes.
2. The network event detection method according to claim 1, characterized in that, the step of constructing an event relationship attribute time subgraph according to the multiple extracted node attributes includes: connecting the original graph nodes with the same node attributes according to the edge relationship type to obtain multiple connected nodes; determining edge relationships corresponding to the multiple connected nodes, and constructing an event relationship attribute time subgraph according to the multiple edge relationships and the timestamp in the five-tuple attribute.
3. The network event detection method according to claim 2, characterized in that, the multiple connected nodes at least include: a first connected node, a second connected node, and a third connected node, and the number of the first connected node, the second connected node, and the third connected node is multiple. The step of connecting the original graph nodes with the same node attributes according to the edge relationship type to obtain multiple connected nodes includes: obtaining a first node attribute, a second node attribute, and a third node attribute in the edge relationship type; connecting the original graph nodes with the same node attributes as the first node attribute to obtain a first connected node; connecting the original graph nodes with the same node attributes as the second node attribute to obtain a second connected node; connecting the original graph nodes with the same node attributes as the third node attribute to obtain a third connected node.
4. The network event detection method according to claim 2, characterized in that the step of constructing an event relationship attribute time subgraph according to the plurality of edge relationships and the timestamps in the five-tuple attributes includes: constructing an event relationship attribute graph according to the plurality of edge relationships; dividing the event relationship attribute graph according to the timestamps, and using the divided event relationship attribute graph as an event relationship attribute time subgraph.
5. The network event detection method according to claim 1, characterized in that the step of performing graph representation learning on the target graph nodes according to a preset edge relationship type to obtain the feature representation data of the target graph nodes includes: finding the target edge relationship corresponding to the target graph node from the event relationship attribute time subgraph according to the edge relationship type, and determining the target node attribute corresponding to the target graph node; calculating the found target edge relationship and the target node attribute according to a preset specific algorithm to obtain a set of neighbor graph nodes adjacent to the target graph node; obtaining the set attributes corresponding to the set of neighbor graph nodes, and aggregating the target node attributes, the set attributes and the target edge relationship according to a preset aggregation function to obtain the feature representation data of the target graph nodes.
6. The network event detection method according to claim 1, characterized in that the step of detecting the target network event according to the feature representation data to obtain the detection result of the target network event includes: obtaining test data of the target network event according to the feature representation data and a preset activation function; judging whether the test data is within a preset network normal threshold range; if the test data is within the network normal threshold range, determining that the detection result is normal network communication; if the test data is not within the network normal threshold range, determining that the detection result is abnormal network communication, and obtaining the network attack type corresponding to the detection result.
7. A network event detection device, characterized in that the network event detection device includes: a construction module, configured to construct an event relationship attribute time subgraph according to the original log data in a plurality of original network events, and the step of constructing an event relationship attribute time subgraph according to the original log data in a plurality of original network events includes: performing identification processing on the original log data in the plurality of original network events according to the five-tuple attributes to obtain original graph nodes corresponding to the respective original network events; obtaining a plurality of remaining attributes other than the five-tuple attributes; calculating the respective remaining attributes according to a preset information gain algorithm to obtain information gain values corresponding to the respective remaining attributes; arranging the plurality of information gain values in descending order to obtain a gain arrangement table; extracting node attributes corresponding to the respective original graph nodes from the gain arrangement table according to the descending order of the gain arrangement table and a preset extraction quantity; and constructing an event relationship attribute time subgraph according to the extracted plurality of node attributes; A search module, configured to search for target log data in a target network event from the event relationship attribute time sub-graph according to a preset five-tuple attribute, so as to obtain a target graph node corresponding to the target network event, where the target network event refers to any one of a plurality of original network events, and the five-tuple attribute includes a source IP address, a source port number, a target IP address, a target port number, and a timestamp; A learning module, configured to perform graph representation learning on the target graph node according to a preset edge relationship type, so as to obtain feature representation data of the target graph node; A detection module, configured to detect the target network event according to the feature representation data, so as to obtain a detection result of the target network event.
8. A terminal device characterized in that the terminal device includes a memory, a processor, and a network event detection program stored on the memory and executable on the processor, and when the processor executes the network event detection program, the steps of the network event detection method according to any one of claims 1 to 6 are implemented.
9. A computer storage medium characterized in that a network event detection program is stored on the computer storage medium, and when the network event detection program is executed by a processor, the steps of the network event detection method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Web attack stage analysis method and system based on Web log
CN114915479A