Network threat detection method and apparatus, and storage medium
By acquiring user access behavior data and historical operation and maintenance data, and utilizing behavioral feature and type detection models, the behavior and type of network threats are automatically analyzed, solving the problem of low efficiency in the detection of unknown threats in existing technologies and achieving efficient network threat detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2023-02-07
- Publication Date
- 2026-06-02
AI Technical Summary
Existing technologies struggle to detect unknown cyber threats and require manual processing and analysis, making it difficult to handle large amounts of cyber threat data and resulting in low detection efficiency.
By acquiring user access behavior data and historical operation and maintenance data, and using behavioral feature detection and type detection models, the behavioral and type information of network threats can be determined, thereby determining the threat level.
It improves the efficiency of network threat detection, can automatically analyze unknown threats, and reduces manual intervention.
Smart Images

Figure CN116208400B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method, apparatus and storage medium for network threat detection. Background Technology
[0002] With the development of internet communication technology, enterprise information security has become increasingly important. Current cyber threats are becoming more diversified, covert, and organized. As enterprises expand, the amount of cyber threat data generated by their systems also increases.
[0003] Current network threat detection methods struggle to detect unknown network threats, still require manual processing and analysis, and are unable to handle the large volume of network threat data every day, resulting in low detection efficiency. Summary of the Invention
[0004] This application provides a network threat detection method, apparatus, and storage medium, which can solve the problem of low detection efficiency in the prior art.
[0005] To achieve the above objectives, this application adopts the following technical solution:
[0006] Firstly, this application provides a network threat detection method, which includes: acquiring user access behavior data and historical operation and maintenance data; using user access behavior data to characterize service access characteristics in a communication network; using historical operation and maintenance data to characterize field information of service data; performing behavioral feature detection on user access behavior data to determine behavioral information of network threats; identifying network threat feature fields based on historical operation and maintenance data to determine the type information of network threats; and determining the threat level of network threats based on the behavioral information and type information of network threats.
[0007] Based on the above technical solution, the network threat detection device provided in this application acquires user access behavior data and historical operation and maintenance data. The user access behavior data characterizes the service access characteristics in the communication network, while the historical operation and maintenance data characterizes the field information of the service data. In this way, the network threat detection device can perform behavioral feature detection on the user access behavior data to determine the behavioral information of network threats, and identify network threat feature fields based on the historical operation and maintenance data to determine the type information of the network threat. Subsequently, the network threat detection device can determine the threat level of the network threat based on its behavioral and type information. Therefore, this application improves the efficiency of network threat detection by performing network threat detection on both behavioral and feature data.
[0008] In conjunction with the first aspect mentioned above, in one possible implementation, the method includes: inputting user access behavior data into a behavior detection model to determine behavioral information of network threats.
[0009] In conjunction with the first aspect above, in one possible implementation, the behavior detection model includes multiple access features and the attack behavior corresponding to each access feature; the method includes: determining the existing target access feature from user access behavior data; the target access feature is any one or more access features among the multiple access features; and when the target access feature meets preset conditions, determining the network threat behavior information as the attack behavior corresponding to the target access feature.
[0010] In conjunction with the first aspect mentioned above, in one possible implementation, the method includes: inputting historical operation and maintenance data into a type detection model to determine the type information of network threats.
[0011] In conjunction with the first aspect mentioned above, in one possible implementation, the type detection model includes multiple network threat feature fields and the attack type corresponding to each network threat feature field; the method includes: when the historical operation and maintenance data includes the target network threat feature field, determining the type information of the network threat as the attack type corresponding to the target network threat feature field; the target network threat feature field is any one or more of the multiple network threat feature fields.
[0012] In conjunction with the first aspect mentioned above, in one possible implementation, the method further includes: triggering a network threat work order dispatch operation when the threat level of the network threat is the target level; the network threat work order is used to instruct the handling of the network threat.
[0013] Secondly, this application provides a network threat detection device, which includes: a communication unit and a processing unit; the communication unit is used to acquire user access behavior data and historical operation and maintenance data; the user access behavior data is used to characterize the service access characteristics in the communication network; the historical operation and maintenance data is used to characterize the field information of the service data; the processing unit is used to perform behavioral feature detection on the user access behavior data to determine the behavioral information of network threats; the processing unit is also used to identify network threat feature fields based on the historical operation and maintenance data to determine the type information of network threats; the processing unit is also used to determine the threat level of network threats based on the behavioral information and type information of network threats.
[0014] In conjunction with the second aspect above, in one possible implementation, the processing unit is used to: input user access behavior data into the behavior detection model to determine the behavioral information of network threats.
[0015] In conjunction with the second aspect above, in one possible implementation, the behavior detection model includes multiple access features and the attack behavior corresponding to each access feature; the processing unit is used to: determine the target access feature from the user access behavior data; the target access feature is any one or more of the multiple access features; and when the target access feature meets preset conditions, determine the network threat behavior information as the attack behavior corresponding to the target access feature.
[0016] In conjunction with the second aspect above, in one possible implementation, the processing unit is used to: input historical operation and maintenance data into the type detection model to determine the type information of network threats.
[0017] In conjunction with the second aspect above, in one possible implementation, the type detection model includes multiple network threat feature fields and the attack type corresponding to each network threat feature field; the processing unit is used to: determine the type information of the network threat as the attack type corresponding to the target network threat feature field when the historical operation and maintenance data includes the target network threat feature field; the target network threat feature field is any one or more of the multiple network threat feature fields.
[0018] In conjunction with the second aspect above, in one possible implementation, the processing unit is used to: trigger a network threat work order dispatch operation when the threat level of the network threat is the target level; the network threat work order is used to instruct the handling of the network threat.
[0019] Thirdly, this application provides a network threat detection device, which includes: a processor and a communication interface; the communication interface and the processor are coupled, and the processor is used to run computer programs or instructions to implement the network threat detection method as described in the first aspect and any possible implementation of the first aspect.
[0020] Fourthly, this application provides a computer-readable storage medium storing instructions that, when executed on a terminal, cause the terminal to perform the network threat detection method as described in the first aspect and any possible implementation thereof.
[0021] Fifthly, this application provides a computer program product containing instructions that, when run on a network threat detection device, causes the network threat detection device to perform the network threat detection method as described in the first aspect and any possible implementation thereof.
[0022] In a sixth aspect, this application provides a chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run computer programs or instructions to implement the network threat detection method as described in the first aspect and any possible implementation thereof.
[0023] Specifically, the chip provided in this application also includes a memory for storing computer programs or instructions.
[0024] It should be noted that the aforementioned computer instructions may be stored, in whole or in part, on a computer-readable storage medium. This computer-readable storage medium may be packaged together with the processor of the device, or it may be packaged separately from the processor of the device; this application does not impose any limitation on this.
[0025] In a seventh aspect, this application provides a network threat detection system, comprising: a network threat detection device and a data server, wherein the network threat detection device is used to perform the network threat detection method as described in the first aspect and any possible implementation thereof.
[0026] The descriptions of aspects two through seven in this application can be referenced to the detailed description of aspect one; and the beneficial effects of the descriptions of aspects two through seven can be referenced to the analysis of the beneficial effects of aspect one, which will not be repeated here.
[0027] In this application, the names of the aforementioned network threat detection devices do not limit the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear under other names. As long as the functions of each device or functional module are similar to those in this application, they fall within the scope of the claims of this application and their equivalents.
[0028] These or other aspects of this application will become more readily apparent in the following description. Attached Figure Description
[0029] Figure 1 This is a schematic diagram of the architecture of a network threat detection system provided in an embodiment of this application;
[0030] Figure 2 This is a schematic diagram of a data interface provided in an embodiment of this application;
[0031] Figure 3 A flowchart illustrating a network threat detection method provided in this application embodiment;
[0032] Figure 4 A flowchart illustrating another network threat detection method provided in this application embodiment;
[0033] Figure 5A flowchart illustrating another network threat detection method provided in this application embodiment;
[0034] Figure 6 This is a schematic diagram of the structure of a network threat detection device provided in an embodiment of this application;
[0035] Figure 7 This is a schematic diagram of another network threat detection device provided in an embodiment of this application. Detailed Implementation
[0036] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0037] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0038] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.
[0039] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.
[0040] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0041] In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0042] With the development of internet communication technology, enterprise information security has become increasingly important. Current cyber threats are becoming more diversified, covert, and organized. The formation of cyber threat chains means that single-method information security detection and protection are insufficient to meet the current information security threat landscape.
[0043] Although most enterprises have established identity authentication systems, information security defense systems, and security risk monitoring systems, which basically ensure the secure operation of information data and application services on the network, these systems generate a large amount of security threat data every day, making it difficult for relevant technical personnel to handle effectively.
[0044] Currently, the relevant technologies mainly have the following problems:
[0045] 1. Related technologies can usually only detect known network threats, and have difficulty detecting unknown network threats.
[0046] 2. Related technologies typically use big data analytics and machine learning to build threat detection models. However, due to a lack of security operation and maintenance data related to telecommunications services, the trained threat detection models are difficult to adapt to the characteristic data of business systems.
[0047] 3. The relevant technologies require the deployment of dedicated hardware devices to achieve network threat detection, such as sensors.
[0048] In summary, current network threat detection methods are inadequate for detecting unknown network threats, still require manual processing and analysis, struggle to handle the large volume of network threat data daily, and have low detection efficiency.
[0049] In view of this, this application provides a network threat detection method, apparatus, and storage medium. The network threat detection apparatus acquires user access behavior data and historical operation and maintenance data. The user access behavior data characterizes the service access characteristics in the communication network, and the historical operation and maintenance data characterizes the field information of the service data. In this way, the network threat detection apparatus can perform behavioral feature detection on the user access behavior data to determine the behavioral information of network threats, and identify network threat feature fields based on the historical operation and maintenance data to determine the type information of the network threat. Subsequently, the network threat detection apparatus can determine the threat level of the network threat based on the behavioral and type information. Therefore, this application improves the efficiency of network threat detection by performing network threat detection on both behavioral and feature data.
[0050] Figure 1 This is an architecture diagram of a network threat detection system 10 provided in an embodiment of this application. Figure 1 As shown, the network threat detection system 10 includes a network threat detection device 11 and a data server 12.
[0051] The network threat detection device 11 and the data server 12 are connected by a communication link, which can be a wired communication link or a wireless communication link. This application does not limit the type of communication link.
[0052] In one possible implementation, the various device modules in the network threat detection system 10 provided in this application embodiment can communicate with each other via a data interface.
[0053] For example, such as Figure 2 As shown, Figure 2 This is a schematic diagram of a data interface provided in an embodiment of this application.
[0054] Interface A is the data interface between data server 12 and log receiving module 1101. Cluster probe 1201, Web probe 1202, gateway 1203, traffic probe 1204, antivirus center 1205, and DNS 1207 can send logs to log receiving module 1101 via the SYSLOG protocol.
[0055] Interface B is the data interface between data server 12 and scan scheduling module 1107. Scan scheduling module 1107 manages and executes scan tasks for the probes by calling the RESTful interface provided by asset probe 1106 / missed scan probe 1208.
[0056] Interface C is the interface for the log transmission module. The log receiving module 1101 sends the received logs to the log transmission module 1102 through interface C. The log transmission module 1102 queues the received logs and sends them to the corresponding log parsing module 1103 / detection service module (e.g., the statistical detection module 1104 and the feature detection module 1105) through the queue.
[0057] Interface D is the log database interface. Through the RESTful interface provided by log database 1108, the log parsing module 1103 and the detection service module can store log data. The statistics module 1106 and the web application can read relevant data through interface D.
[0058] Interface E is the business database interface. Through the database interface provided by business database 1109, statistics module 1106 and scan scheduling module 1107 can read relevant configuration management information and store statistical data. Web applications can read relevant system management data through interface E.
[0059] Interface F is the vulnerability database interface. The scan scheduling module 1107 stores the scan results by calling interface F, and the web application reads the scan results through interface F.
[0060] It should be noted that the network threat detection method provided in this application embodiment can be applied to the network threat detection device 11 described above. The network threat detection device 11 can be an independent communication device, such as an access network device or a core network device. The network threat detection device 11 can also be a functional module coupled to the access network device. The network threat detection device 11 can also be a computer program (application, APP) for executing the network threat detection method. The network threat detection device 11 can also be a server connected to the access network device.
[0061] When the network threat detection device 11 is an access network device, the network threat detection device 11 is a device located on the access network side of the communication system and has wireless transceiver function, or a chip or chip system that can be installed in the device. Access network equipment includes, but is not limited to: access points (APs) in WiFi systems, such as home gateways, routers, servers, switches, and bridges; evolved NodeBs (eNBs), radio network controllers (RNCs), NodeBs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home evolved NodeBs or home NodeBs, HNBs), base band units (BBUs), wireless relay nodes, wireless backhaul nodes, transmission and reception points (TRPs or transmission points, TPs), etc. It can also be 5G base stations, such as gNBs in new radio (NR) systems, or transmission points (TRPs or TPs), one or a group of antenna panels (including multiple antenna panels) of a 5G base station, or network nodes constituting gNBs or transmission points, such as base band units, distributed units (DUs), or roadside units with base station functions. Access network equipment includes sideunits (RSUs) and 5G access network (NG radio access network, NG-Ran) equipment. Access network equipment also includes base stations in different networking modes, such as master evolved NodeBs (MeNBs) and secondary eNBs (SeNBs, or secondary gNBs, SgNBs). Access network equipment also includes different types, such as terrestrial base stations, airborne base stations, and satellite base stations.
[0062] When the network threat detection device 11 is a core network device, it is located on the core network side of the communication system. The core network device can be a physical device or a virtual device. Core network devices for 4G networks include, but are not limited to: Mobility Management Entity (MME), Serving Gateway (SGW), and Public Data Network Gateway (PGW). Core network devices for 5G networks include, but are not limited to: Access and Mobility Management Function (AMF), Session Management Function (SMF), and User Plane Function (UPF).
[0063] When the network threat detection device 11 is a server, the server includes:
[0064] The processor can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program in this application.
[0065] A transceiver can be any type of transceiver used to communicate with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area network (WLAN), etc.
[0066] Memory can be read-only memory (ROM) or other types of static storage devices capable of storing static information and instructions, random access memory (RAM) or other types of dynamic storage devices capable of storing information and instructions, electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed discs, laser discs, optical discs, universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory can exist independently and be connected to the processor via communication lines. Memory can also be integrated with the processor.
[0067] Data server 12 is used to collect network data.
[0068] The network threat detection device 11 is used to acquire user access behavior data and historical operation and maintenance data.
[0069] User access behavior data is used to characterize the service access characteristics in the communication network. Historical operation and maintenance data is used to characterize the field information of service data.
[0070] For example, the network threat detection device 11 can obtain user access behavior data and historical operation and maintenance data from the data server 12.
[0071] The network threat detection device 11 is also used to detect the behavioral characteristics of user access behavior data to determine the behavioral information of network threats.
[0072] The network threat detection device 11 is also used to identify network threat characteristic fields based on historical operation and maintenance data to determine the type information of network threats.
[0073] The network threat detection device 11 is also used to determine the threat level of a network threat based on its behavioral and type information.
[0074] As one possible implementation, such as Figure 1As shown, the network threat detection device 11 includes: a log receiving module 1101, a log transmission module 1102, a log parsing module 1103, a statistical detection module 1104, a feature detection module 1105, a statistics module 1106, a scan scheduling module 1107, a log database 1108, a business database 1109, and a vulnerability database 1110. The data server 12 includes: a cluster probe 1201, a web probe 1202, a gateway 1203, a traffic probe 1204, an antivirus center 1205, an asset probe 1206, a domain name system (DNS) 1207, and a vulnerability scan probe 1208.
[0075] The log receiving module 1101 is used to collect log data.
[0076] For example, the log receiving module 1101 can obtain cluster logs from the cluster probe 1201, web access logs from the web probe 1202, antivirus logs from the gateway 1203, endpoint antivirus center logs from the antivirus center 1205, and DNS logs from the DNS 1207.
[0077] For example, the log receiving module 1101 can be an RSyslog service function module.
[0078] Cluster probe 1201 is used to send cluster logs to network threat detection device 11.
[0079] For example, cluster probe 1201 can be a honeypot cluster probe.
[0080] Web probe 1202 can be used with WBE service middleware such as Apache, Tomcat, and Weblogic to send web access logs to network threat detection device 11.
[0081] Gateway 1203 is used to send network antivirus logs to network threat detection device 11.
[0082] For example, gateway 1203 can be a Topsec antivirus gateway device.
[0083] Traffic probe 1204 is used to send traffic detection alarm logs to network threat detection device 11.
[0084] For example, the traffic probe 1204 can be a network traffic analysis and detection device.
[0085] The antivirus center 1205 is used to collect virus logs on terminal devices and send the virus logs to the network threat detection device 11.
[0086] For example, the antivirus center 1205 can be the Symantec Endpoint Virus Management Center.
[0087] The asset probe 1206 and the vulnerability probe 1208 are used to send asset and vulnerability scanning results to the network threat detection device 11.
[0088] For example, asset probe 1206 can be an Nmap asset probe, and miss probe 1208 can be a Nessus or AWVS miss probe.
[0089] DNS1207 can be a DNS server used to send DNS request logs to the network threat detection device 11.
[0090] The log transmission module 1102 is used to transmit the acquired log data.
[0091] For example, the log transmission module can be a system data bus, such as Kafka.
[0092] The log parsing module 1103 is used to segment, process, and transform log data.
[0093] For example, the log parsing module 1103 can be a Logstash service function module.
[0094] The statistical detection module 1104, the feature detection module 1105, and the statistical module 1106 are used for correlation analysis, evidence collection analysis, and rule auditing of massive, heterogeneous, and multi-type data.
[0095] For example, data analysis and visualization for virus security risk management platforms, DNS analysis, web access log detection and analysis, daily traffic analysis, vulnerability scanning management, and asset scanning systems.
[0096] Among them, the statistical detection module 1104 and the feature detection module 1105, based on business access features, train a preset model from historical data of business security operation and maintenance through machine learning methods, and then detect network threats through the trained preset model.
[0097] The statistical detection module 1104 and the feature detection module 1105 are also used to store the detection results in the log database 1108.
[0098] Log database 1108 is used to store data information after parsing and processing various logs.
[0099] For example, log database 1108 can be an Elasticsearch database.
[0100] The statistics module 1106 is used to obtain log data from the log database 1108, extract business data from it, and store it in the business database 1109.
[0101] Business database 1109 is used to store business statistics data and business system configuration management data.
[0102] For example, business database 1109 can be a PostgreSQL database.
[0103] The scan scheduling module 1107 is used to automatically generate scan tasks based on the configuration of the foreground application, and to schedule, execute, acquire and parse the scan results according to the preset time.
[0104] Vulnerability database 1110 is used to store vulnerability scan results.
[0105] For example, vulnerability database 1110 can be a MongoDB database.
[0106] The web application is a web application management program used to display the various functions of the network threat detection device 11 through software.
[0107] In one possible implementation, the network threat detection device 11 also includes a configuration management library and a work order system.
[0108] The configuration management library is used to manage the asset configuration of the telecommunications business system, and the work order system is used to trigger the automatic dispatch of work orders.
[0109] For example, the configuration management library can be a CMDB database.
[0110] It should be noted that the various embodiments of this application can be referenced or learned from each other. For example, the same or similar steps, method embodiments, system embodiments and device embodiments can be referenced from each other without limitation.
[0111] Figure 3 This is a flowchart illustrating a network threat detection method provided in an embodiment of this application. Figure 3 As shown, the method includes the following steps:
[0112] Step 301: The network threat detection device acquires user access behavior data and historical operation and maintenance data.
[0113] User access behavior data is used to characterize the service access characteristics in the communication network. Historical operation and maintenance data is used to characterize the field information of service data.
[0114] In one possible implementation, the network threat detection device can obtain collected network log information from a data server and extract user access behavior data and historical operation and maintenance data from the network log information.
[0115] For example, a network threat detection device can perform data preprocessing operations on network log information. These preprocessing operations may include missing data imputation, standardization, and anomaly removal.
[0116] Subsequently, the network threat detection device performs data segmentation and transformation on the preprocessed network log information to obtain user access behavior data and historical operation and maintenance data.
[0117] Step 302: The network threat detection device performs behavioral feature detection on user access behavior data to determine the behavioral information of network threats.
[0118] Among them, the behavioral information of the network threat is used to characterize the attack behavior of the network threat.
[0119] For example, cyber threat attacks may include malicious scanning, directory traversal, web crawlers, administrative address guessing, structured query language (SQL) injection, password brute-force attacks, webshells, data breaches, and other attack behaviors.
[0120] Web crawlers are programs or scripts that automatically retrieve information from the web according to certain rules. However, frequent web crawling can affect the normal operation of websites and pose a network threat to users.
[0121] SQL injection refers to an attack that inserts SQL commands into the query string of a web form submission, domain name input, or header request, thereby tricking the server into executing malicious SQL commands. SQL injection can compromise a user's database security.
[0122] A webshell is an attack that gains access to a server by exploiting an open port. Webshells are also known as script trojans.
[0123] Step 303: The network threat detection device identifies network threat characteristic fields based on historical operation and maintenance data to determine the type information of the network threat.
[0124] Among them, the network threat type information is used to characterize the attack type of the network threat.
[0125] For example, types of cyber threats can include database attacks (such as SQL injection and MSSQL injection), shellshock attacks, web penetration, error code expansion, cross-site scripting (XSS) attacks, and web attacks.
[0126] Among them, shell-breaking attacks use bash to process certain commands, thereby allowing attackers to execute arbitrary code on the bash version.
[0127] Web penetration refers to a type of attack that targets a specific network in order to obtain data and perform other network-related actions.
[0128] Cross-site scripting (XSS) is a type of code injection attack where attackers inject malicious scripts into a target website, causing the malicious scripts to be executed when users browse the website, thereby threatening the user's network security.
[0129] Step 304: The network threat detection device determines the threat level of the network threat based on the network threat's behavioral and type information.
[0130] The threat level of a network threat is used to characterize the severity of that threat. A higher threat level indicates a greater severity, and vice versa. The threat level can be represented by a numerical value within a preset range or by different labels; this application does not limit this representation.
[0131] It should be noted that, as described above, the behavioral information of a network threat is used to characterize its attack behavior, and the type information of a network threat is used to characterize its attack type. Therefore, the network threat detection device in this application can analyze the threat level of a network threat based on its attack behavior and attack level.
[0132] In one possible implementation, after step 304, the method further includes: if the threat level of the network threat is the target level, the network threat detection device triggers a network threat work order dispatch operation.
[0133] Among them, the network threat ticket is used to instruct the handling of network threats.
[0134] For example, network threats can be categorized into low, medium, and high threat levels. Targets are categorized as medium and high threat levels.
[0135] At this point, if the network threat level is medium or high, the network threat detection device will trigger a network threat work order dispatch operation.
[0136] Based on the above technical solution, the network threat detection device provided in this application acquires user access behavior data and historical operation and maintenance data. The user access behavior data characterizes the service access characteristics in the communication network, while the historical operation and maintenance data characterizes the field information of the service data. In this way, the network threat detection device can perform behavioral feature detection on the user access behavior data to determine the behavioral information of network threats, and identify network threat feature fields based on the historical operation and maintenance data to determine the type information of the network threat. Subsequently, the network threat detection device can determine the threat level of the network threat based on its behavioral and type information. Therefore, this application improves the efficiency of network threat detection by performing network threat detection on both behavioral and feature data.
[0137] The following describes the process by which network threat detection devices determine behavioral information about network threats.
[0138] As one possible embodiment of this application, combined with Figure 3 ,like Figure 4 As shown, step 302 above can also be achieved through step 401.
[0139] Step 401: The network threat detection device inputs user access behavior data into the behavior detection model to determine the behavioral information of network threats.
[0140] The behavior detection model includes multiple access features and the attack behavior corresponding to each access feature.
[0141] In one possible implementation, the network threat detection device can identify target access features from user access behavior data, and if the target access features meet preset conditions, determine the network threat behavior information as the attack behavior corresponding to the target access features.
[0142] The target access feature is any one or more access features among multiple access features.
[0143] For example, the correspondence between access characteristics and attack behaviors can be represented by the following Table 1:
[0144] Table 1. Correspondence between access characteristics and attack behaviors
[0145]
[0146] The single IP access count refers to the number of accesses from a specific IP address. When the single IP access count exceeds the initial count, the network threat detection device determines the network threat behavior as malicious scanning and directory traversal.
[0147] Single IP access depth refers to the number of different pages on a target website accessed by a single IP address in a single visit. When the single IP access depth exceeds a preset depth, the network threat detection device identifies the network threat behavior as web crawling and directory traversal.
[0148] Single IP access bandwidth refers to the number of target websites accessed by a single IP address in a single visit. When the single IP access bandwidth exceeds the preset bandwidth, the network threat detection device identifies network threat behavior as web crawling, directory traversal, and management address guessing.
[0149] The percentage of non-2xx response requests refers to the proportion of response requests with status codes other than 2xx. Since status codes 2xx represent normal responses, the percentage of non-2xx response requests can represent the proportion of abnormal response requests. When the percentage of non-2xx response requests exceeds a first threshold, the network threat detection device determines that the network threat behavior information is directory traversal and management address guessing.
[0150] "Same URL, different parameters" refers to accessing the same URL address using different parameters. When the same URL with different parameters exists, network threat detection devices identify the network threat behavior as SQL injection and password brute-force attacks.
[0151] The number of times the same URL is accessed across different domains refers to the number of times different domains are accessed through the same URL. When the number of times the same URL is accessed across different domains exceeds a certain threshold, the network threat detection device identifies the network threat behavior as SQL injection and password brute-force attacks.
[0152] Upload / download traffic is used to characterize the resource access behavior of users. When the deviation value of upload / download traffic exceeds the first value, the network threat detection device determines the network threat behavior as Webshell and data leakage.
[0153] The number of POST requests without a Referer header refers to the number of POST requests that lack the Referer header field. The Referer header field is typically used to identify the source of access; POST requests without a Referer header field cannot identify the source of access, thus increasing the likelihood of a network threat. When the number of POST requests without a Referer exceeds three times, the network threat detection device determines the network threat behavior to be SQL injection, password brute-force, or data leakage.
[0154] Single-IP traffic anomaly refers to abnormal access traffic from a specific IP address. When the traffic from a single IP address exceeds that of a second IP address, the network threat detection device determines the network threat behavior to be a data breach.
[0155] Based on the above technical solution, the network threat detection device in this application can input user access behavior data into a behavior detection model to determine the behavioral information of network threats. Since the behavior detection model includes multiple access features and the corresponding attack behaviors for each access feature, this application can determine the currently existing target access feature from the user access behavior data, thereby identifying the network threat's behavioral information as the attack behavior corresponding to that target access feature. In summary, the network threat detection device in this application identifies attack behaviors based on the correspondence between access features and attack behaviors, improving the identification effect of network threat behavioral information.
[0156] The following describes the process by which a network threat detection device determines the type of network threat.
[0157] As one possible embodiment of this application, combined with Figure 3 ,like Figure 5 As shown, step 303 above can also be achieved through the following step 501.
[0158] Step 501: The network threat detection device inputs historical operation and maintenance data into the type detection model to determine the type information of the network threat.
[0159] The type detection model includes multiple network threat feature fields and the attack type corresponding to each network threat feature field.
[0160] In one possible implementation, the network threat detection device can determine the type of network threat as the attack type corresponding to the target network threat feature field when the historical operation and maintenance data includes the target network threat feature field.
[0161] The target network threat feature field can be any one or more of the multiple network threat feature fields.
[0162] For example, the correspondence between network threat characteristic fields and attack types can be represented by the following Table 2:
[0163] Table 2. Correspondence between network threat characteristic fields and attack types
[0164]
[0165] Different attack types correspond to network threat feature fields in historical operation and maintenance data. Therefore, network threat detection devices can match existing network threat feature fields in historical operation and maintenance data to determine the attack type of network threats.
[0166] Based on the above technical solution, the network threat detection device in this application can input historical operation and maintenance data into a type detection model to determine the type information of network threats. Since this type detection model includes multiple network threat feature fields and the attack type corresponding to each network threat feature field, this application can match the currently existing target network threat feature fields from historical operation and maintenance data, thereby determining the type information of the network threat as the attack type corresponding to that target network threat feature field. In summary, the network threat detection device in this embodiment of the application identifies attack types based on the correspondence between network threat feature fields and attack types, improving the identification effect of network threat type information.
[0167] This application embodiment can divide the network threat detection device into functional modules or functional units according to the above method examples. For example, each function can be divided into its own functional modules or functional units, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module or functional unit. The module or unit division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0168] like Figure 6 The diagram shown is a structural schematic of a network threat detection device 60 provided in an embodiment of this application. The network threat detection device 60 includes:
[0169] The communication unit 602 is used to acquire user access behavior data and historical operation and maintenance data; the user access behavior data is used to characterize the service access characteristics in the communication network; the historical operation and maintenance data is used to characterize the field information of the service data.
[0170] The processing unit 601 is used to perform behavioral feature detection on user access behavior data to determine the behavioral information of network threats.
[0171] The processing unit 601 is also used to identify network threat characteristic fields based on historical operation and maintenance data and determine the type information of network threats.
[0172] The processing unit 601 is also used to determine the threat level of a network threat based on the network threat's behavioral information and type information.
[0173] In one possible implementation, the processing unit 601 is used to: input user access behavior data into the behavior detection model to determine the behavioral information of network threats.
[0174] In one possible implementation, the behavior detection model includes multiple access features and the attack behavior corresponding to each access feature; the processing unit 601 is used to: determine the existing target access feature from the user access behavior data; the target access feature is any one or more access features among the multiple access features; and when the target access feature meets preset conditions, determine the network threat behavior information as the attack behavior corresponding to the target access feature.
[0175] In one possible implementation, the processing unit 601 is used to: input historical operation and maintenance data into the type detection model to determine the type information of network threats.
[0176] In one possible implementation, the type detection model includes multiple network threat feature fields and the attack type corresponding to each network threat feature field; the processing unit 601 is used to: determine the type information of the network threat as the attack type corresponding to the target network threat feature field when the historical operation and maintenance data includes the target network threat feature field; the target network threat feature field is any one or more of the multiple network threat feature fields.
[0177] In one possible implementation, the processing unit 601 is used to: trigger a network threat work order dispatch operation when the threat level of the network threat is the target level; the network threat work order is used to instruct the handling of the network threat.
[0178] When implemented in hardware, the communication unit 602 in this embodiment can be integrated onto the communication interface, and the processing unit 601 can be integrated onto the processor. Specific implementation methods are as follows: Figure 7 As shown.
[0179] Figure 7 A schematic diagram of another possible structure of the network threat detection device involved in the above embodiments is shown. The network threat detection device 70 includes a processor 702 and a communication interface 703. The processor 702 is used to control and manage the operation of the network threat detection device 70, for example, executing the steps performed by the processing unit 601, and / or performing other processes of the technology described herein. The communication interface 703 is used to support communication between the network threat detection device 70 and other network entities, for example, executing the steps performed by the communication unit 602. The network threat detection device 70 may also include a memory 701 and a bus 704. The memory 701 is used to store the program code and data of the network threat detection device 70.
[0180] The memory 701 may be the memory in the network threat detection device 70, and the memory may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as read-only memory, flash memory, hard disk or solid-state drive; the memory may also include a combination of the above types of memory.
[0181] The processor 702 described above can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements computing functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0182] The 704 bus can be an Extended Industry Standard Architecture (EISA) bus, etc. The 704 bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 7 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0183] Figure 7 The network threat detection device 70 in the middle can also be a chip. The chip includes one or more processors 702 and a communication interface 703.
[0184] In some embodiments, the chip further includes a memory 701, which may include read-only memory and random access memory, and provides operation instructions and data to the processor 702. A portion of the memory 701 may also include non-volatile random access memory (NVRAM).
[0185] In some implementations, memory 701 stores elements such as execution modules or data structures, or subsets thereof, or extended sets thereof.
[0186] In this embodiment of the application, the corresponding operation is executed by calling the operation instructions stored in the memory 701 (the operation instructions can be stored in the operating system).
[0187] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0188] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to execute the network threat detection method described in the above method embodiments.
[0189] This application also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the network threat detection method in the method flow shown in the above method embodiments.
[0190] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: electrical connections having one or more wires; portable computer disks; hard disks; random access memory (RAM); read-only memory (ROM); erasable programmable read-only memory (EPROM); registers; hard disks; optical fibers; portable compact disc read-only memory (CD-ROM); optical storage devices; magnetic storage devices; or any suitable combination thereof; or any other form of computer-readable storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In the embodiments of this application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0191] Since the network threat detection device, computer-readable storage medium, and computer program product in the embodiments of this application can be applied to the above method, the technical effects they can achieve can also be referred to the above method embodiments. The embodiments of this application will not be repeated here.
[0192] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0193] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0194] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0195] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for detecting network threats, characterized in that, The method includes: Acquire user access behavior data and historical operation and maintenance data; the user access behavior data is used to characterize the service access characteristics in the communication network; the historical operation and maintenance data is used to characterize the field information of the service data; The user access behavior data is input into the behavior detection model, which includes multiple access features and the attack behavior corresponding to each access feature. Determine the target access feature from the user access behavior data; the target access feature is any one or more of the plurality of access features. If the target access characteristics meet preset conditions, the network threat behavior information is determined to be the attack behavior corresponding to the target access characteristics; The historical operation and maintenance data is input into the type detection model, which includes multiple network threat feature fields and the attack type corresponding to each network threat feature field. If the historical operation and maintenance data includes a target network threat feature field, the type information of the network threat is determined to be the attack type corresponding to the target network threat feature field; the target network threat feature field is any one or more of the plurality of network threat feature fields. The threat level of the network threat is determined based on its behavioral and type information.
2. The method according to claim 1, characterized in that, The method further includes: If the threat level of the network threat is at the target level, a network threat ticket dispatch operation is triggered; the network threat ticket is used to instruct the handling of the network threat.
3. A network threat detection device, characterized in that, Includes a communication unit and a processing unit; The communication unit is used to acquire user access behavior data and historical operation and maintenance data; the user access behavior data is used to characterize the service access characteristics in the communication network; the historical operation and maintenance data is used to characterize the field information of the service data. The processing unit is configured to input the user access behavior data into a behavior detection model, the behavior detection model including multiple access features and attack behaviors corresponding to each access feature; determine the target access feature from the user access behavior data; the target access feature is any one or more of the multiple access features; and, if the target access feature meets preset conditions, determine the network threat behavior information as the attack behavior corresponding to the target access feature. The processing unit is further configured to input the historical operation and maintenance data into a type detection model, the type detection model including multiple network threat feature fields and an attack type corresponding to each network threat feature field; when the historical operation and maintenance data includes a target network threat feature field, the type information of the network threat is determined to be the attack type corresponding to the target network threat feature field; the target network threat feature field is any one or more of the multiple network threat feature fields. The processing unit is further configured to determine the threat level of the network threat based on the network threat's behavioral information and type information.
4. The apparatus according to claim 3, characterized in that, The processing unit is used for: If the threat level of the network threat is at the target level, a network threat ticket dispatch operation is triggered; the network threat ticket is used to instruct the handling of the network threat.
5. A network threat detection device, characterized in that, include: A processor and a communication interface; the communication interface is coupled to the processor, the processor being used to run computer programs or instructions to implement the network threat detection method as described in any one of claims 1-2.
6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed by a computer, enable the computer to perform the network threat detection method as described in any one of claims 1-2.