An intrusion detection method and device, and a computer readable storage medium

By acquiring and analyzing network security data, using pre-defined models to predict rationality and legality, and combining cross-analysis criteria, the need for comprehensive network security analysis is addressed, thereby improving the accuracy of intrusion detection and internal network security.

CN116455589BActive Publication Date: 2026-02-24CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210011314.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-06
Publication Date
2026-02-24
Estimated Expiration
2042-01-06

AI Technical Summary

Technical Problem

Existing technologies cannot meet the high demands of comprehensive analysis in cybersecurity, especially given the frequent business access and security management requirements within large corporations. Process-oriented methods are ineffective in analyzing intrusion events.

Method used

By acquiring relevant security data on object access, the rationality and legality of access paths are predicted using preset standard models and preset comprehensive models. Combined with cross-analysis criteria, the compliance of access paths is determined.

Benefits of technology

It enables accurate analysis of access paths, detects unauthorized and unauthorized operations, and improves the detection capabilities of intranet security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116455589B_ABST
    Figure CN116455589B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an intrusion detection method and device, and a computer readable storage medium, wherein the method comprises: obtaining relevant security data accessed by an object; based on a preset standard model and a preset comprehensive model, performing rationality prediction and legality prediction on an access path of the relevant security data to obtain rationality probability and legality probability; wherein the relevant security data is data formed under the access path when the object accesses; performing operation on the rationality probability and the legality probability through a preset cross analysis criterion to obtain a compliance probability; and comparing the compliance probability with a preset compliance value to determine whether the access path is compliant. In the above scheme, the relevant security data accessed by the object is analyzed, trajectory analysis and cross analysis are realized, the accuracy of the analysis result is ensured, over-authorization and illegal operation behaviors can be effectively found, and thus the attack behavior of intrusion is found, and the internal network security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to an intrusion detection method and apparatus, and a computer-readable storage medium. Background Technology

[0002] Currently, network security primarily focuses on security incident analysis. Intrusion analysis involves collecting raw security data from managed objects within business systems, such as security devices, applications, system devices, and application systems. A procedural approach is used to filter and screen intrusion events layer by layer, effectively identifying the intrusion events. However, with the increasing number of business systems, more frequent business access, and the growing demands of corporate security management, the requirements for network security incident analysis are becoming increasingly stringent. Procedural methods are no longer sufficient to meet the comprehensive analysis requirements of network security. Summary of the Invention

[0003] To address the aforementioned technical problems, embodiments of the present invention provide an intrusion detection method and apparatus, and a computer-readable storage medium, which can solve the comprehensive analysis problem of network security.

[0004] The technical solution of this invention is implemented as follows:

[0005] This invention provides an intrusion detection method, the method comprising:

[0006] Obtain security data related to object access;

[0007] Based on a preset standard model and a preset comprehensive model, the rationality and legality of the access path for the relevant security data are predicted to obtain the rationality probability and legality probability; wherein, the relevant security data is the data formed under the access path when the object accesses it;

[0008] The probability of compliance is obtained by calculating the probability of reasonableness and the probability of legality using a preset cross-analysis criterion.

[0009] The compliance probability is compared with a preset compliance value to determine whether the access path is compliant.

[0010] In the above scheme, before obtaining the relevant security data for object access, the method further includes:

[0011] Obtain basic security data related to object access from log files;

[0012] The relevant basic security data are aggregated and classified to obtain basic behavioral data, basic system resources, basic access path data, and basic traffic information;

[0013] The basic behavioral data, the basic system resources, the basic access path data, and the basic traffic information are identified and sorted to obtain the relevant security data.

[0014] In the above scheme, the relevant security data includes behavioral data, system resources, access path data, and traffic information;

[0015] The process of predicting the rationality and legality of access paths for the relevant security data based on a preset standard model and a preset comprehensive model, and obtaining rationality and legality probabilities, includes:

[0016] Based on the behavioral data, the access path data, and the traffic information, the rationality of the access path is predicted using a preset standard model to obtain the rationality probability.

[0017] Based on the behavioral data and the traffic information, the legality of the access path is predicted using a preset comprehensive model to obtain the legality probability.

[0018] In the above scheme, before performing path rationality and legality prediction on the relevant security data based on a preset standard model and a preset comprehensive model to obtain the rationality probability and legality probability, the method further includes:

[0019] Retrieve historical security data related to access to the same object;

[0020] Based on the aforementioned historical security data, classification, identification, and sorting processes are performed to obtain the historical security data.

[0021] Based on the historical security data, the initial standard model is continuously trained until the first expected indicator is reached, and the preset standard model is determined.

[0022] Based on the historical security data, the initial integrated model is continuously trained until the second expected indicator is reached, and the preset integrated model is determined.

[0023] In the above scheme, the process of classifying, identifying, and sorting the historically relevant basic security data to obtain the historically relevant security data includes:

[0024] Based on the aforementioned historical basic security data, classification processing is performed to obtain historical basic behavior data, historical basic system resources, historical basic access path data, and historical basic traffic information.

[0025] Based on the historical basic behavior data, the historical basic system resources, the historical basic access path data, and the historical basic traffic information, identification and sorting processes are performed to obtain the historical related security data.

[0026] In the above scheme, the step of continuously training the initial standard model based on the historical relevant security data until the first expected indicator is reached, and then determining the preset standard model, includes:

[0027] Based on the aforementioned historical security data, a reasonableness prediction is performed using the initial standard model to obtain the probability of a reasonable path and the probability of an unreasonable path.

[0028] Based on the probability of the reasonable path and the probability of the unreasonable path, the preset standard model is determined by comparing it with the first expected indicator.

[0029] In the above scheme, the first expected indicator includes a first preset value and a second preset value;

[0030] The step of determining the preset standard model by comparing the probabilities of the reasonable path and the unreasonable path with the first expected indicator includes:

[0031] If the probability of the reasonable path is greater than the first preset value, and the probability of the unreasonable path is less than the second preset value, then the model is saved to obtain the preset standard model.

[0032] If the probability of the reasonable path is not greater than the first preset value, and / or the probability of the unreasonable path is not less than the second preset value, then training continues until the probability of the reasonable path is greater than the first preset value and the probability of the unreasonable path is less than the second preset value. Then the model is saved to obtain the preset standard model.

[0033] In the above scheme, the step of continuously training the initial comprehensive model based on the historical relevant security data until the second expected indicator is reached, and then determining the preset comprehensive model, includes:

[0034] Based on the aforementioned historical security data, legality prediction is performed using the initial integrated model to obtain the probability of a legal path and the probability of an illegal path.

[0035] Based on the probabilities of the legal paths and the illegal paths, the preset comprehensive model is determined by comparing them with the second expected index.

[0036] In the above scheme, the second expected indicator includes a third preset value and a fourth preset value;

[0037] The step of determining the preset standard model by comparing the probabilities of the legal paths and the illegal paths with the second expected index includes:

[0038] If the probability of the legal path is greater than the third preset value, and the probability of the illegal path is less than the fourth preset value, then the model is saved to obtain the preset comprehensive model.

[0039] If the probability of the legal path is not greater than the third preset value, and / or the probability of the illegal path is not less than the fourth preset value, then training continues until the probability of the legal path is greater than the third preset value and the probability of the illegal path is less than the fourth preset value. The model is then saved to obtain the preset comprehensive model.

[0040] In the above scheme, comparing the compliance probability with a preset compliance value to determine whether the access path is compliant includes:

[0041] If the compliance probability is greater than the preset compliance value, then the access path is determined to be compliant;

[0042] If the compliance probability is not greater than the preset compliance value, then the access path is determined to be non-compliant.

[0043] This invention provides an intrusion detection device, including an acquisition unit and a judgment unit; wherein,

[0044] The acquisition unit is used to acquire relevant security data of object access; based on a preset standard model and a preset comprehensive model, it performs reasonableness prediction and legality prediction on the access path of the relevant security data to obtain reasonableness probability and legality probability; wherein, the relevant security data is the data formed under the access path when the object accesses; through a preset cross-analysis criterion, it calculates the reasonableness probability and the legality probability to obtain compliance probability;

[0045] The judgment unit is used to compare the compliance probability with a preset compliance value to determine whether the access path is compliant.

[0046] This invention provides an intrusion detection device, comprising:

[0047] Memory, used to store executable instructions;

[0048] A processor is configured to execute executable instructions stored in the memory, and when the executable instructions are executed, the processor executes the intrusion detection method.

[0049] This invention provides a computer-readable storage medium storing executable instructions. When the executable instructions are executed by one or more processors, the processors execute the intrusion detection method.

[0050] This invention provides an intrusion detection method and apparatus, and a computer-readable storage medium. The method includes: acquiring relevant security data of object access; predicting the rationality and legality of the access path based on a preset standard model and a preset comprehensive model, obtaining rationality probability and legality probability; wherein the relevant security data is data formed under the access path when the object accesses the data; calculating the rationality probability and legality probability using a preset cross-analysis criterion to obtain a compliance probability; and comparing the compliance probability with a preset compliance value to determine whether the access path is compliant. The above solution analyzes the relevant security data of object access, realizing trajectory analysis and cross-analysis, ensuring the accuracy of the analysis results; it can effectively detect unauthorized and illegal operations, thereby detecting intrusion attacks and improving intranet security. Attached Figure Description

[0051] Figure 1 An optional flowchart of an intrusion detection method provided in an embodiment of the present invention. Figure 1 ;

[0052] Figure 2(a) is an optional prediction data diagram of an intrusion detection method provided in an embodiment of the present invention;

[0053] Figure 2(b) is an optional path information diagram of an intrusion detection method provided in an embodiment of the present invention;

[0054] Figure 3 A second optional flowchart of an intrusion detection method provided in an embodiment of the present invention;

[0055] Figure 4 An optional flowchart of an intrusion detection method provided in an embodiment of the present invention. Figure 3 ;

[0056] Figure 5 An optional flowchart of an intrusion detection method provided in an embodiment of the present invention. Figure 4 ;

[0057] Figure 6 An optional flowchart of an intrusion detection method provided in an embodiment of the present invention. Figure 5 ;

[0058] Figure 7 A schematic diagram of the structure of an intrusion detection device provided in an embodiment of the present invention. Figure 1 ;

[0059] Figure 8 The second schematic diagram shows the structure of an intrusion detection device provided in an embodiment of the present invention. Detailed Implementation

[0060] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of the present invention.

[0061] To enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. Figure 1 This is an optional flowchart of an intrusion detection method provided in an embodiment of the present invention. Figure 1 , will combine Figure 1 The steps shown are explained.

[0062] S101. Obtain relevant security data for object access.

[0063] In some embodiments of the present invention, the relevant security data includes behavioral data, system resources, access path data, and traffic information; the object is generally a user, but the embodiments of the present invention are not limited thereto.

[0064] In some embodiments of the present invention, the intrusion detection method is applicable to scenarios involving security analysis of network attack events.

[0065] In some embodiments of the present invention, the terminal can obtain security data related to object access.

[0066] S102. Based on the preset standard model and the preset comprehensive model, predict the rationality and legality of the access path for the relevant security data, and obtain the rationality probability and legality probability.

[0067] In some embodiments of the present invention, the preset standard model is obtained by training the initial standard model with historical related security data of the same object; the preset comprehensive model is obtained by training the initial comprehensive model with historical related security data of the same object; the related security data is the data formed under the access path when the object is accessed.

[0068] In some embodiments of the present invention, the terminal can use a preset standard model to predict the rationality of the access path based on behavioral data, access path data, and traffic information, and obtain a rationality probability; and use a preset comprehensive model to predict the legality of the access path based on behavioral data and traffic information, and obtain a legality probability.

[0069] In some embodiments of the present invention, S102 can be implemented by S1021 and S1022, as follows:

[0070] S1021. Based on behavioral data, access path data, and traffic information, the rationality of the access path is predicted using a preset standard model to obtain the rationality probability.

[0071] In some embodiments of the present invention, the terminal can input behavioral data, access path data and traffic information into a preset standard model, and use the preset standard model to predict the rationality of the access path to obtain the rationality probability of the access path.

[0072] S1022. Based on behavioral data and traffic information, the legality of the access path is predicted through a preset comprehensive model to obtain the legality probability.

[0073] In some embodiments of the present invention, the terminal can input behavioral data and traffic information into a preset comprehensive model, and use the preset comprehensive model to predict the legality of the access path to obtain the legality probability of the access path.

[0074] It is understood that, in some embodiments of the present invention, the terminal can use behavioral data, access path data, and traffic information to predict the rationality of the access path using a preset standard model, and obtain the rationality probability; and use behavioral data and traffic information to predict the legality of the access path using a preset comprehensive model, and obtain the legality probability, thus laying the groundwork for obtaining the compliance probability in the future.

[0075] S103. Using preset cross-analysis criteria, calculate the probability of reasonableness and the probability of legality to obtain the probability of compliance.

[0076] In some embodiments of the present invention, the preset cross-analysis criteria are formed by reconstructing samples based on the prediction results of a preset standard model and a preset comprehensive model.

[0077] In some embodiments of the present invention, the terminal can calculate the compliance probability by using the reasonableness probability and the legality probability through a preset cross-analysis criterion.

[0078] For example, the preset cross-analysis criteria can be obtained by the following formula (1).

[0079] P{X=x, Y=y}=p(X,Y;θ) (1)

[0080] Where θ is an unknown parameter; P is a sample reconstructed based on the results of the preset standard model X and the preset comprehensive model Y, and the population XY is a discrete probability distribution.

[0081] For example, the compliance probability can be obtained by the following formula (2).

[0082] L(θ)=L(x1,x2,..,xn;y1,y2,..,yn)=πp(xi,yi;θ) (2)

[0083] Here, (x1,x2,...,xn) is a set of observations of (X1,X2,...,Xn); (y1,y2,...,yn) is a set of observations of (Y1,Y2,...,Yn); L(θ) is the likelihood function of the sample, which also represents the compliance probability; (X1,X2,...,Xn) and (Y1,Y2,...,Yn) are samples of size n taken from the population, and πp(Xi,Yi,θ) is the joint distribution law of X and Y.

[0084] S104. Compare the compliance probability with the preset compliance value to determine whether the access path is compliant.

[0085] In some embodiments of the present invention, the preset compliance value is set in advance.

[0086] In some embodiments of the present invention, the terminal can compare the compliance probability with a preset compliance value. If the compliance probability is greater than the preset compliance value, the access path is judged to be compliant; if the compliance probability is not greater than the preset compliance value, the access path is judged to be non-compliant.

[0087] For example, the preset compliance value can be obtained by finding the maximum value of formula (2). The value θ that makes formula (2) reach its maximum value is calculated. The specific calculation process can be obtained through the following formula (3).

[0088] β=arg max L(θ)=arg maxπp(xi,yi,θ) (3)

[0089] Where β is the maximum value; πp(Xi,Yi,θ) is the joint distribution law of X and Y.

[0090] For ease of analysis, the log-likelihood function is defined as shown in formula (4).

[0091] H(θ)=ln L(θ) (4)

[0092] Where H(θ) is the logarithm of the likelihood function; L(θ) is the likelihood function of the sample.

[0093] For example, the value of θ can be obtained by the following formula (5).

[0094]

[0095] Where β is the maximum value; H(θ) is the logarithm of the likelihood function; and L(θ) is the likelihood function of the sample. The calculated value of θ maximizes the probability L(θ), and the value of L(θ) is the preset compliance value for determining the path.

[0096] It is understood that, in some embodiments of the present invention, the terminal can obtain relevant security data on object access; based on a preset standard model and a preset comprehensive model, it can predict the rationality and legality of the access path for the relevant security data, and obtain the rationality probability and legality probability; through a preset cross-analysis criterion, it can calculate the rationality probability and legality probability to obtain the compliance probability; it can compare the compliance probability with a preset compliance value to determine whether the access path is compliant; it can analyze the relevant security data on object access, realize trajectory analysis and cross-analysis, and ensure the accuracy of the analysis results; it can effectively detect unauthorized and illegal operation behaviors, thereby detecting intrusion attack behaviors and improving intranet security.

[0097] In some embodiments of the present invention, S104 can be implemented by S1041 and S1042, as follows:

[0098] S1041. If the compliance probability is greater than the preset compliance value, the access path is judged to be compliant.

[0099] In some embodiments of the present invention, the terminal can compare the compliance probability with a preset compliance value. If the compliance probability is greater than the preset compliance value, the access path is determined to be compliant.

[0100] S1042. If the compliance probability is not greater than the preset compliance value, the access path is judged as non-compliant.

[0101] In some embodiments of the present invention, the terminal can compare the compliance probability with a preset compliance value. If the compliance probability is not greater than the preset compliance value, the access path is judged to be non-compliant.

[0102] For example, Figure 2(a) is an optional prediction data graph of an intrusion detection method provided in an embodiment of the present invention. As shown in Figure 2(a), behavioral data includes account, personnel, role, organization, login, operation, and business data; traffic information includes source IP, port, destination IP and port, and access (business type, port); access path information includes secure access and application (antivirus, firewall, etc.); system resources include IP, MAC address, route, switch information, static and dynamic routing information.

[0103] For example, Figure 2(b) is an optional path information diagram of an intrusion detection method provided by an embodiment of the present invention. The terminal can use behavioral data, system resources, access path data, and traffic information to predict and analyze the operation path from point A to point D. As shown in Figure 2(b), the horizontal axis represents time, the vertical axis represents operation, and the bisector between the horizontal and vertical axes represents the path. There are three paths in Figure 2(b), and their path information is as follows: the route of path 1 is ACBD, the route of path 2 is ABCD, and the route of path 3 is ABCD. However, the operations performed on paths 2 and 3 are different. Through predictive analysis, it can be found that path 1 is a normal operation path, while paths 2 and 3 are unreasonable or illegal operations. By using preset cross-analysis criteria, alarms can be generated for the analysis of paths 2 and 3.

[0104] It is understood that, in some embodiments of the present invention, the terminal can compare the compliance probability with a preset compliance value. If the compliance probability is greater than the preset compliance value, the access path is judged to be compliant; if the compliance probability is not greater than the preset compliance value, the access path is judged to be non-compliant. This can effectively detect illegal operation behaviors, thereby detecting intrusion attack behaviors and improving intranet security.

[0105] In some embodiments of the present invention Figure 3 This is a schematic diagram of an optional flowchart of an intrusion detection method provided in an embodiment of the present invention, as shown below. Figure 3 As shown, S105, S106, and S107 are executed before S101, as follows:

[0106] S105. Obtain basic security data related to object access through log files.

[0107] In some embodiments of the present invention, the relevant basic security data includes accounts, personnel, roles, organizations, logins, operations, services, IP addresses, MAC addresses, routes, switch information, static routing information, dynamic routing information, secure access, source IP addresses, source ports, destination IP addresses, destination ports, etc.

[0108] In some embodiments of the present invention, the terminal can obtain basic security data related to object access from log files.

[0109] S106. Aggregate and classify relevant basic security data to obtain basic behavioral data, basic system resources, basic access path data, and basic traffic information.

[0110] In some embodiments of the present invention, basic behavioral data specifically includes data such as accounts, personnel, roles, organizations, logins, operations, and business; basic system resources specifically include IP, MAC addresses, routes, switch information, static routing information, and dynamic routing information; basic access path data specifically includes secure access, applications (antivirus, firewall), etc.; and basic traffic information specifically includes source IP, source port, destination IP, destination port, etc.

[0111] In some embodiments of the present invention, the terminal can obtain basic behavioral data, basic system resources, basic access path data and basic traffic information by aggregating and classifying relevant basic security data.

[0112] S107. The basic behavioral data, basic system resources, basic access path data, and basic traffic information are identified and sorted to obtain relevant security data.

[0113] In some embodiments of the present invention, the terminal can identify the process in which basic behavioral data, basic system resources, basic access path data, and basic traffic information are located to obtain identification data; and then obtain relevant security data by sorting the identification data.

[0114] It is understood that, in some embodiments of the present invention, the terminal can obtain relevant basic security data on object access through log files; aggregate and classify the relevant basic security data to obtain basic behavior data, basic system resources, basic access path data, and basic traffic information; and perform identification and sorting processing on the basic behavior data, basic system resources, basic access path data, and basic traffic information to obtain relevant security data, providing a basis for subsequent judgment on whether the access path is compliant.

[0115] In some embodiments of the present invention Figure 4 This is an optional flowchart of an intrusion detection method provided in an embodiment of the present invention. Figure 3 ,like Figure 4 As shown, S108-S1011 are executed before S102, as follows:

[0116] S108. Obtain historical basic security data related to access to the same object.

[0117] In some embodiments of the present invention, historically relevant basic security data is data generated from 3-6 months of user access and operation logs for the same object. Specifically, historically relevant basic security data includes historical accounts, personnel, roles, organizations, logins, operations, services, IP addresses, MAC addresses, routes, switch information, static routing information, dynamic routing information, secure access, source IP address, source port, destination IP address, destination port, etc.

[0118] In some embodiments of the present invention, the terminal can obtain historical basic security data related to the access of the same object through historical log files.

[0119] S109. Based on historical relevant basic security data, perform classification, identification, and sorting processes to obtain historical relevant security data.

[0120] In some embodiments of the present invention, the terminal can classify historical basic security data to obtain historical basic behavior data, historical basic system resources, historical basic access path data, and historical basic traffic information; and then identify and sort these historical basic behavior data, historical basic system resources, historical basic access path data, and historical basic traffic information to obtain historical related security data.

[0121] In some embodiments of the present invention, S109 can be implemented by S1091 and S1092, as follows:

[0122] S1091. Based on historical relevant basic security data, perform classification processing to obtain historical basic behavior data, historical basic system resources, historical basic access path data, and historical basic traffic information.

[0123] In some embodiments of the present invention, historical basic behavioral data specifically includes historical data such as accounts, personnel, roles, organizations, logins, operations, and business; historical basic system resources specifically include historical IP, MAC addresses, routes, switch information, static routing information, and dynamic routing information; historical basic access path data specifically includes historical secure access, applications (antivirus, firewall), etc.; and historical basic traffic information specifically includes historical source IP, source port, destination IP, destination port, etc.

[0124] In some embodiments of the present invention, the terminal can classify and process historical basic security data to obtain historical basic behavior data, historical basic system resources, historical basic access path data, and historical basic traffic information.

[0125] S1092. Based on historical basic behavior data, historical basic system resources, historical basic access path data, and historical basic traffic information, perform identification and sorting processing to obtain historical related security data.

[0126] In some embodiments of the present invention, the terminal can identify the process in which historical basic behavior data, historical basic system resources, historical basic access path data, and historical basic traffic information are located to obtain historical identification data; and then obtain historical related security data by sorting the historical identification data.

[0127] It is understood that, in some embodiments of the present invention, the terminal can classify and process historical basic security data to obtain historical basic behavior data, historical basic system resources, historical basic access path data, and historical basic traffic information; and then perform identification and sorting processing on the historical basic behavior data, historical basic system resources, historical basic access path data, and historical basic traffic information to obtain historical related security data, providing training data for determining the preset standard model and the preset comprehensive model.

[0128] S1010. Based on historical relevant security data, continuously train the initial standard model until the first expected indicator is reached, and determine the preset standard model.

[0129] In some embodiments of the present invention, the first expected index includes a first preset value and a second preset value; the initial standard model is a machine learning model based on a Bayesian filter.

[0130] In some embodiments of the present invention, the terminal can use an initial standard model to predict the rationality of historical security data, and obtain the probability of a reasonable path and the probability of an unreasonable path; the probability of a reasonable path and the probability of an unreasonable path are compared with a first expected indicator to determine the preset standard model.

[0131] For example, both the first and second preset values ​​are set to 85%.

[0132] In some embodiments of the present invention Figure 5 This is an optional flowchart of an intrusion detection method provided in an embodiment of the present invention. Figure 4 ,like Figure 5 As shown, S1010 can be implemented through S10101-S10102, as follows:

[0133] S10101. Based on historical relevant security data, a reasonableness prediction is made through an initial standard model to obtain the probability of a reasonable path and the probability of an unreasonable path.

[0134] In some embodiments of the present invention, the terminal can use an initial standard model to predict the reasonableness of historical security data and obtain the probability of a reasonable path and the probability of an unreasonable path.

[0135] S10102. Based on the probability of a reasonable path and the probability of an unreasonable path, a preset standard model is determined by comparing it with the first expected indicator.

[0136] In some embodiments of the present invention, the terminal can compare the probability of a reasonable path with a first preset value to obtain a first comparison result; compare the probability of an unreasonable path with a second preset value to obtain a second comparison result; and determine a preset standard model based on the first comparison result and the second comparison result.

[0137] It is understood that, in some embodiments of the present invention, the terminal can use historical relevant security data to make a reasonableness prediction using an initial standard model, thereby obtaining the probability of a reasonable path and the probability of an unreasonable path; by comparing the probability of a reasonable path and the probability of an unreasonable path with a first expected indicator, a preset standard model is determined, providing a basis for predicting the reasonableness probability of the access path.

[0138] In some embodiments of the present invention, S10102 can be implemented by S101021-S101022, as follows:

[0139] S101021. If the probability of a reasonable path is greater than the first preset value and the probability of an unreasonable path is less than the second preset value, then save the model and obtain the preset standard model.

[0140] In some embodiments of the present invention, the terminal can compare the probability of a reasonable path with a first preset value and the probability of an unreasonable path with a second preset value; if the probability of a reasonable path is greater than the first preset value and the probability of an unreasonable path is less than the second preset value, the model at this time is saved and used as a preset standard model.

[0141] S101022. If the probability of a reasonable path is not greater than the first preset value, and / or the probability of an unreasonable path is not less than the second preset value, then continue training until the probability of a reasonable path is greater than the first preset value and the probability of an unreasonable path is less than the second preset value, save the model, and obtain the preset standard model.

[0142] In some embodiments of the present invention, the terminal can compare the probability of a reasonable path with a first preset value and the probability of an unreasonable path with a second preset value. If the probability of a reasonable path is not greater than the first preset value or the probability of an unreasonable path is not less than the second preset value, then training continues until the probability of a reasonable path is greater than the first preset value and the probability of an unreasonable path is less than the second preset value. The model at this point is then saved and used as a preset standard model.

[0143] It is understood that, in some embodiments of the present invention, the terminal can compare the probability of a reasonable path with a first preset value and compare the probability of an unreasonable path with a second preset value, thereby determining a preset standard model and providing a basis for predicting the reasonableness of subsequent access paths.

[0144] S1011. Based on historical and relevant security data, continuously train the initial integrated model until the second expected indicator is reached, and determine the preset integrated model.

[0145] In some embodiments of the present invention, the second expected index includes a third preset value and a fourth preset value; the initial comprehensive model is based on the 5W1H analysis model.

[0146] In some embodiments of the present invention, the terminal can use an initial comprehensive model to predict the legality of historical security data, obtain the probability of a legal path and the probability of an illegal path; compare the probability of a legal path and the probability of an illegal path with a second expected index to determine the preset comprehensive model.

[0147] For example, both the third and fourth preset values ​​are set to 85%.

[0148] It is understood that, in some embodiments of the present invention, the terminal can obtain historical related basic security data of the same object access; classify, identify and sort the historical related basic security data to obtain historical related security data; continuously train the initial standard model with the historical related security data until the first expected indicator is reached, and determine the preset standard model; continuously train the initial comprehensive model with the historical related security data until the second expected indicator is reached, and determine the preset comprehensive model, so as to provide a basis for subsequent prediction of access paths and obtain the probability of rationality and the probability of legality.

[0149] In some embodiments of the present invention Figure 6 This is an optional flowchart of an intrusion detection method provided in an embodiment of the present invention. Figure 5 ,like Figure 6 As shown, S1011 can be implemented through S10111-S10112, as follows:

[0150] S10111. Based on historical security data, legality prediction is performed using an initial integrated model to obtain the probability of a legal path and the probability of an illegal path.

[0151] In some embodiments of the present invention, the terminal can use an initial comprehensive model to predict the legality of historical security data and obtain the probability of a legal path and the probability of an illegal path.

[0152] S10112. Based on the probabilities of legal paths and illegal paths, the preset comprehensive model is determined by comparing them with the second expected index.

[0153] In some embodiments of the present invention, the terminal can compare the probability of a legal path with a third preset value to obtain a third comparison result; compare the probability of an illegal path with a fourth preset value to obtain a fourth comparison result; and determine a preset comprehensive model based on the third and fourth comparison results.

[0154] It is understood that, in some embodiments of the present invention, the terminal can use historical relevant security data to perform legality prediction using an initial comprehensive model, thereby obtaining the probability of a legal path and the probability of an illegal path; by comparing the probabilities of legal and illegal paths with a second expected indicator, a preset comprehensive model is determined, providing a basis for predicting the legality probability of the access path.

[0155] In some embodiments of the present invention, S10112 can be implemented by S101121-S101122, as follows:

[0156] S101121. If the probability of a valid path is greater than the third preset value and the probability of an invalid path is less than the fourth preset value, then save the model and obtain the preset comprehensive model.

[0157] In some embodiments of the present invention, the terminal can compare the probability of a valid path with a third preset value and the probability of an invalid path with a fourth preset value; if the probability of a valid path is greater than the third preset value and the probability of an invalid path is less than the fourth preset value, the model at this time is saved and used as a preset comprehensive model.

[0158] S101122. If the probability of a valid path is not greater than the third preset value, and / or the probability of an invalid path is not less than the fourth preset value, then continue training until the probability of a valid path is greater than the third preset value and the probability of an invalid path is less than the fourth preset value. Save the model and obtain the preset comprehensive model.

[0159] In some embodiments of the present invention, the terminal can compare the probability of a valid path with a third preset value and the probability of an invalid path with a fourth preset value. If the probability of a valid path is not greater than the third preset value or the probability of an invalid path is not less than the fourth preset value, then training continues until the probability of a valid path is greater than the third preset value and the probability of an invalid path is less than the fourth preset value. The model at this point is then saved and used as the preset comprehensive model.

[0160] It is understood that, in some embodiments of the present invention, the terminal can compare the probability of a legitimate path with a third preset value and compare the probability of an illegitimate path with a fourth preset value to determine a preset comprehensive model, thereby providing a basis for predicting the legitimacy of subsequent access paths.

[0161] The following will describe an exemplary application of the embodiments of the present invention in a practical application scenario.

[0162] In some embodiments of the present invention, the intrusion detection method may include the following steps:

[0163] 1. Obtain relevant security data for object access.

[0164] In some embodiments of the present invention, the terminal can obtain behavioral data (4A, login, operation, business data), system resources (IP, MAC address, route, switch information, static and dynamic routing information), access path data (secure access application (antivirus, firewall, etc.)) results and traffic information (source IP, source port, destination IP, destination port) and other related security data.

[0165] 2. Study the rationality and legality of the access path through relevant security data.

[0166] In some embodiments of the present invention, the terminal can obtain the probability of the access path's rationality by comprehensively analyzing behavioral data, access path data, and traffic information through a preset standard model; and obtain the probability of the access path's legality by comprehensively analyzing behavioral data and traffic information through a preset comprehensive model.

[0167] 3. Based on reasonableness and legality, and using preset cross-analysis criteria, determine whether the access path is compliant.

[0168] In some embodiments of the present invention, the terminal can obtain the compliance probability by using a preset cross-analysis criterion based on the reasonableness probability and the legality probability; and determine whether the access path is compliant by comparing the compliance probability with the preset compliance value.

[0169] It is understood that, in some embodiments of the present invention, the terminal can access relevant security data through the object; study the rationality and legality of the access path through the relevant security data; and determine whether the access path is compliant by using preset cross-analysis criteria based on the rationality and legality. This makes the security analysis more rigorous and accurate, detects unauthorized and illegal access operations, and meets the needs of intrusion detection analysis.

[0170] Based on the intrusion detection method described in the above embodiments, this invention also provides an intrusion detection device, such as... Figure 7 The above, Figure 7 A schematic diagram of the structure of an intrusion detection device provided in an embodiment of the present invention. Figure 1 The device 7 includes: an acquisition unit 701 and a judgment unit 702; wherein,

[0171] The acquisition unit 701 is used to acquire relevant security data of object access; based on a preset standard model and a preset comprehensive model, it performs reasonableness prediction and legality prediction on the access path of the relevant security data to obtain reasonableness probability and legality probability; wherein, the relevant security data is the data formed under the access path when the object accesses; through a preset cross-analysis criterion, it calculates the reasonableness probability and the legality probability to obtain compliance probability;

[0172] The judgment unit 702 is used to compare the compliance probability with a preset compliance value to determine whether the access path is compliant.

[0173] In some embodiments of the present invention, the acquisition unit 701 is used to acquire relevant basic security data of object access through log files; to aggregate and classify the relevant basic security data to obtain basic behavior data, basic system resources, basic access path data and basic traffic information; and to perform identification and sorting processing on the basic behavior data, the basic system resources, the basic access path data and the basic traffic information to obtain the relevant security data.

[0174] In some embodiments of the present invention, the relevant security data includes behavioral data, system resources, access path data, and traffic information; the acquisition unit 701 is used to predict the rationality of the access path based on the behavioral data, the access path data, and the traffic information using a preset standard model to obtain the rationality probability; and to predict the legality of the access path based on the behavioral data and the traffic information using a preset comprehensive model to obtain the legality probability.

[0175] In some embodiments of the present invention, the intrusion detection device further includes a determination unit 703; wherein,

[0176] The acquisition unit 701 is used to acquire historical related basic security data of the same object access; based on the historical related basic security data, it performs classification processing, identification processing and sorting processing to obtain historical related security data;

[0177] The determining unit 703 is used to continuously train the initial standard model based on the historical relevant security data until a first expected indicator is reached, and to determine the preset standard model; and to continuously train the initial comprehensive model based on the historical relevant security data until a second expected indicator is reached, and to determine the preset comprehensive model.

[0178] In some embodiments of the present invention, the acquisition unit 701 is used to perform classification processing based on the historical related basic security data to obtain historical basic behavior data, historical basic system resources, historical basic access path data and historical basic traffic information; and to perform identification processing and sorting processing based on the historical basic behavior data, the historical basic system resources, the historical basic access path data and the historical basic traffic information to obtain the historical related security data.

[0179] In some embodiments of the present invention, the acquisition unit 701 is used to perform a rationality prediction based on the historical relevant security data and the initial standard model to obtain the probability of a rational path and the probability of an unreasonable path.

[0180] The determining unit 703 is used to determine the preset standard model by comparing the probability of the reasonable path and the probability of the unreasonable path with the first expected indicator.

[0181] In some embodiments of the present invention, the first expected index includes a first preset value and a second preset value; the acquisition unit 701 is used to save the model and obtain the preset standard model if the probability of the reasonable path is greater than the first preset value and the probability of the unreasonable path is less than the second preset value; if the probability of the reasonable path is not greater than the first preset value and / or the probability of the unreasonable path is not less than the second preset value, then training continues until the probability of the reasonable path is greater than the first preset value and the probability of the unreasonable path is less than the second preset value, then the model is saved and the preset standard model is obtained.

[0182] In some embodiments of the present invention, the acquisition unit 701 is used to perform legality prediction based on the historical relevant security data and the initial comprehensive model to obtain the probability of a legal path and the probability of an illegal path.

[0183] The determining unit 703 is used to determine the preset comprehensive model by comparing the probability of the legal path and the probability of the illegal path with the second expected index.

[0184] In some embodiments of the present invention, the second expected index includes a third preset value and a fourth preset value; the acquisition unit 701 is used to save the model and obtain the preset comprehensive model if the probability of the legal path is greater than the third preset value and the probability of the illegal path is less than the fourth preset value; if the probability of the legal path is not greater than the third preset value and / or the probability of the illegal path is not less than the fourth preset value, then training continues until the probability of the legal path is greater than the third preset value and the probability of the illegal path is less than the fourth preset value, then the model is saved and the preset comprehensive model is obtained.

[0185] In some embodiments of the present invention, the judgment unit 702 is used to determine that the access path is compliant if the compliance probability is greater than the preset compliance value, and to determine that the access path is non-compliant if the compliance probability is not greater than the preset compliance value.

[0186] It should be noted that the intrusion detection device provided in the above embodiments is applied to a terminal. The division of the above-described program modules is only used as an example for intrusion detection. In practical applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. Furthermore, the intrusion detection device and the intrusion detection method embodiments provided in the above embodiments belong to the same concept. For details of their specific implementation process and beneficial effects, please refer to the method embodiments, which will not be repeated here. For technical details not disclosed in this device embodiment, please refer to the description of the method embodiments of this invention for understanding.

[0187] Based on the intrusion detection method described in the above embodiments, this invention also provides an intrusion detection device, such as... Figure 8 As shown, Figure 8 The second schematic diagram of an intrusion detection device provided in an embodiment of the present invention includes: a processor 801 and a memory 802; the memory 802 stores one or more programs executable by the processor, and when one or more programs are executed, the processor 801 executes any of the intrusion detection methods described in the previous embodiments.

[0188] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0189] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0190] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0191] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1The steps of the function specified in one or more boxes.

[0192] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention.

Claims

1. An intrusion detection method, characterized in that, include: Obtain relevant security data for object access; wherein, the relevant security data includes behavioral data, system resources, access path data, and traffic information; Based on the behavioral data, the access path data, and the traffic information, the rationality of the access path is predicted using a preset standard model to obtain a rationality probability. The preset standard model is based on historical relevant security data. A rationality prediction is performed using an initial standard model to obtain the probability of a rational path and the probability of an unreasonable path. The probability of a rational path and the probability of an unreasonable path are compared with a first expected indicator. Based on the behavioral data and the traffic information, the legality of the access path is predicted using a preset comprehensive model to obtain a legality probability. The preset comprehensive model is based on historical relevant security data and uses an initial comprehensive model to predict legality, obtaining the probability of a legal path and the probability of an illegal path. The probability of a legal path and the probability of an illegal path are then compared with a second expected indicator. The sample is reconstructed based on the reasonableness probability and the legality probability, the likelihood function of the sample is determined based on the reconstructed sample, and the compliance probability is obtained by solving the likelihood function of the sample. The compliance probability is compared with a preset compliance value to determine whether the access path is compliant.

2. The method according to claim 1, characterized in that, Before obtaining the relevant security data for object access, the method further includes: Obtain basic security data related to object access from log files; The relevant basic security data are aggregated and classified to obtain basic behavioral data, basic system resources, basic access path data, and basic traffic information; The basic behavioral data, the basic system resources, the basic access path data, and the basic traffic information are identified and sorted to obtain the relevant security data.

3. The method according to claim 1, characterized in that, The method further includes: Retrieve historical security data related to access to the same object; Based on the aforementioned historical security data, classification, identification, and sorting processes are performed to obtain the historical security data.

4. The method according to claim 3, characterized in that, The historical security data is obtained by classifying, identifying, and sorting the historical security data, including: Based on the aforementioned historical basic security data, classification processing is performed to obtain historical basic behavior data, historical basic system resources, historical basic access path data, and historical basic traffic information. Based on the historical basic behavior data, the historical basic system resources, the historical basic access path data, and the historical basic traffic information, identification and sorting processes are performed to obtain the historical related security data.

5. The method according to claim 1, characterized in that, The first expected indicator includes a first preset value and a second preset value; the method further includes: If the probability of the reasonable path is greater than the first preset value, and the probability of the unreasonable path is less than the second preset value, then the model is saved to obtain the preset standard model. If the probability of the reasonable path is not greater than the first preset value, and / or the probability of the unreasonable path is not less than the second preset value, then training continues until the probability of the reasonable path is greater than the first preset value and the probability of the unreasonable path is less than the second preset value. Then the model is saved to obtain the preset standard model.

6. The method according to claim 1, characterized in that, The second expected indicator includes a third preset value and a fourth preset value; the method further includes: If the probability of the legal path is greater than the third preset value, and the probability of the illegal path is less than the fourth preset value, then the model is saved to obtain the preset comprehensive model. If the probability of the legal path is not greater than the third preset value, and / or the probability of the illegal path is not less than the fourth preset value, then training continues until the probability of the legal path is greater than the third preset value and the probability of the illegal path is less than the fourth preset value. The model is then saved to obtain the preset comprehensive model.

7. The method according to claim 1, characterized in that, The step of comparing the compliance probability with a preset compliance value to determine whether the access path is compliant includes: If the compliance probability is greater than the preset compliance value, then the access path is determined to be compliant; If the compliance probability is not greater than the preset compliance value, then the access path is determined to be non-compliant.

8. An intrusion detection device, characterized in that, It includes an acquisition unit and a judgment unit; among which, The acquisition unit is used to acquire relevant security data of object access; wherein, the relevant security data includes behavioral data, system resources, access path data, and traffic information; based on the behavioral data, the access path data, and the traffic information, the reasonableness of the access path is predicted using a preset standard model to obtain a reasonableness probability; wherein, the preset standard model is based on historical relevant security data, and reasonableness prediction is performed using an initial standard model to obtain the probability of a reasonable path and the probability of an unreasonable path, and the probability of a reasonable path and the probability of an unreasonable path are compared with a first expected indicator; based on the behavioral data and the traffic information, the legality of the access path is predicted using a preset comprehensive model to obtain a legality probability; wherein, the preset comprehensive model is based on historical relevant security data, and legality prediction is performed using an initial comprehensive model to obtain the probability of a legal path and the probability of an illegal path; the probability of a legal path and the probability of an illegal path are compared with a second expected indicator; samples are reconstructed based on the reasonableness probability and the legality probability, the likelihood function of the samples is determined based on the reconstructed samples, and the compliance probability is obtained by solving the likelihood function of the samples; The judgment unit is used to compare the compliance probability with a preset compliance value to determine whether the access path is compliant.

9. An intrusion detection device, characterized in that, include: Memory, used to store executable instructions; A processor, when executing executable instructions stored in the memory, implements the method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The storage medium stores executable instructions, which, when executed, cause the processor to perform the method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Abnormal access detection method, device and equipment and computer readable storage medium

    CN108446546A

  • Access path analysis method, device and equipment and medium

    CN110019074A