A traffic adaptive security protection method and device, electronic equipment and medium

By introducing traffic baseline models and generative language large-scale interfaces into network security detection, the problem of low efficiency of network security detection is solved, and efficient distinction and accurate judgment of normal and abnormal traffic are achieved.

CN116668169BActive Publication Date: 2025-10-17WUHAN SIPU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310774916.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-27
Publication Date
2025-10-17
Estimated Expiration
2043-06-27

AI Technical Summary

Technical Problem

Existing network security detection technologies have low efficiency, are difficult to implement real-time analysis, are prone to false positives for legitimate activities, and lack methods to optimize detection effects through baseline rules.

Method used

A traffic baseline model is used to distinguish normal business traffic from abnormal attack traffic, and a generative language large-scale interface is used to assist in judgment, reducing the amount of detection and improving accuracy.

Benefits of technology

The traffic baseline model is used to distinguish between normal and abnormal traffic, reduce the detection volume of large-scale interfaces of generative language, improve detection performance and efficiency, and increase the accuracy of rule judgment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116668169B_ABST
    Figure CN116668169B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of flow self-adapting security protection method, device, electronic equipment and medium, its method includes: obtaining real-time network flow, and real-time network flow is parsed to obtain matchable network flow;Matchable network flow is input into flow baseline model, and the first network flow greater than the preset flow in matchable network flow is distributed to rule matching module by flow baseline model, and the second network flow less than the preset flow in matchable network flow is distributed to generative language large-scale interface by flow baseline model;When determining that there is no attack third network flow in the second network flow in generative language large-scale interface, third network flow is imported into rule matching module;When determining that there is attack flow in the second network flow in generative language large-scale interface, blocking is carried out, and when there is attack flow in the first network flow or third network flow, blocking is carried out.The present application improves the efficiency of detection.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and in particular to a traffic adaptive security protection method and device, electronic equipment and medium. BACKGROUND

[0002] With the continuous development of Internet technology and network applications, network security problems have become increasingly prominent. Network attacks and hacker behavior pose a serious threat to the safety and privacy of enterprises and individuals, resulting in significant economic and reputation losses. Therefore, network security detection has become an increasingly important field.

[0003] The problems of traffic analysis technology are: traffic analysis needs to capture and analyze network traffic, which requires high computing resources and storage resources, and it is difficult to achieve real-time analysis, behavior analysis technology: may misreport some legal activities, such as high traffic, etc., and needs a long time of training and learning, so the efficiency may be low.

[0004] Therefore, there is a lack of a method in the prior art that establishes a baseline through some rules, when the traffic exceeds the baseline, the traffic is connected to a natural language processing engine such as ChatGPT, and the detection effect is optimized through a unique way to improve the detection rate and efficiency. SUMMARY

[0005] Therefore, it is necessary to provide a traffic adaptive security protection method, device, electronic equipment and medium to solve the problem of low detection attack efficiency in the prior art.

[0006] In order to solve the above problems, the present application provides a traffic adaptive security protection method, comprising:

[0007] Obtain real-time network traffic and analyze the real-time network traffic to obtain matchable network traffic;

[0008] Input the matchable network traffic into a traffic baseline model, and based on the traffic baseline model, distribute the first network traffic greater than a preset traffic in the matchable network traffic to a rule matching module, and distribute the second network traffic less than the preset traffic in the matchable network traffic to a generative language large-scale interface;

[0009] When the generative language large-scale interface determines that the third network traffic does not exist in the second network traffic, the third network traffic is imported into the rule matching module;

[0010] When the generative language large-scale interface determines that the fourth network traffic exists in the second network traffic, the fourth network traffic is blocked;

[0011] When the rule matching module or the generative language large-scale interface determines that the fifth network traffic exists in the third network traffic, the fifth network traffic is blocked.

[0012] In some possible implementation manners, the traffic baseline model is used to detect traffic data in which external networks access internal networks.

[0013] In some possible implementation manners, the traffic baseline model assigns second network traffic smaller than the preset traffic in the matchable network traffic to a generative language large-scale interface, including:

[0014] The traffic baseline model assigns second network traffic in which external networks access internal networks at a rate greater than a preset rate to a generative language large-scale interface.

[0015] The traffic baseline model determines external network traffic in which external networks access non-existent resources in internal networks as second network traffic, and assigns the second network traffic to a generative language large-scale interface.

[0016] The traffic baseline model determines external network traffic in which external networks access IP with a unit of digit as second network traffic, and assigns the second network traffic to a generative language large-scale interface.

[0017] In some possible implementation manners, the generative language large-scale interface is obtained by calling a CHATGPT interface.

[0018] In some possible implementation manners, the method further includes marking the blocked traffic to obtain marked traffic, and introducing the marked traffic into a rule matching module or a generative language large-scale interface according to a state of the marked traffic for attack detection.

[0019] In some possible implementation manners, the introducing the marked traffic into a rule matching module or a generative language large-scale interface according to a state of the marked traffic for attack detection includes:

[0020] When the state of the marked traffic is normal, the marked traffic is introduced into a rule matching module for attack detection.

[0021] When the state of the marked traffic is abnormal, the marked traffic is introduced into a generative language large-scale interface for attack detection.

[0022] In another aspect, the present application also provides a traffic adaptive security protection device, including:

[0023] The first module is configured to acquire real-time network traffic and parse the real-time network traffic to obtain matchable network traffic.

[0024] The second module is configured to input the matchable network traffic into a traffic baseline model, distribute first network traffic greater than a preset traffic in the matchable network traffic to a rule matching module based on the traffic baseline model, and distribute second network traffic less than the preset traffic in the matchable network traffic to a generative language large-scale interface.

[0025] The third module is configured to, when the generative language large-scale interface determines that third network traffic in the second network traffic does not exist attack, guide the third network traffic into the rule matching module.

[0026] The fourth module is configured to, when the generative language large-scale interface determines that fourth network traffic in the second network traffic exists attack, block the fourth network traffic.

[0027] The fifth module is configured to, when the rule matching module determines that the first network traffic or the generative language large-scale interface determines that fifth network traffic in the third network traffic exists attack, block the fifth network traffic.

[0028] In another aspect, the present application also provides an electronic device comprising a memory and a processor, wherein,

[0029] The memory is configured to store a program.

[0030] The processor is coupled with the memory and is configured to execute the program stored in the memory to implement the steps of the method for adaptive security protection of traffic.

[0031] In another aspect, the present application also provides a computer readable storage medium for storing computer readable programs or instructions, which can implement the steps of the method for adaptive security protection of traffic when executed by a processor.

[0032] The beneficial effects of the above embodiments are that the method for adaptive security protection of traffic provided by the present application can distinguish normal traffic and abnormal attack traffic by setting a traffic baseline model, reduce the detection amount of the generative language large-scale interface, improve the detection performance, at the same time, introduce the generative language large-scale interface for judgment, reduce the number of rules, improve the accuracy of rule judgment, and thus improve the efficiency of attack detection. BRIEF DESCRIPTION OF DRAWINGS

[0033] Figure 1A method flow chart of an embodiment of a flow adaptive security protection method provided by the present invention;

[0034] Figure 2 A schematic diagram of the system architecture of an embodiment of a flow-adaptive security protection method provided by the present invention;

[0035] Figure 3 A schematic structural diagram of an embodiment of a flow-adaptive safety protection device provided by the present invention;

[0036] Figure 4 This is a schematic structural diagram of an embodiment of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0037] The preferred embodiments of the present invention will be described in detail below in conjunction with the accompanying drawings, wherein the accompanying drawings constitute a part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, and are not used to limit the scope of the present invention.

[0038] Figure 1 A flow chart of an embodiment of a flow adaptive security protection method provided by the present invention is as follows Figure 1 As shown, a traffic adaptive security protection method includes:

[0039] S101, obtaining real-time network traffic, and parsing the real-time network traffic to obtain matching network traffic;

[0040] S102: input the matchable network traffic into a traffic baseline model, and based on the traffic baseline model, allocate first network traffic that is greater than a preset traffic flow in the matchable network traffic to a rule matching module, and allocate second network traffic that is less than the preset traffic flow in the matchable network traffic to a generative language large-scale interface;

[0041] S103: When the generative language large-scale interface determines that there is no third network traffic of the attack in the second network traffic, importing the third network traffic into a rule matching module;

[0042] S104: When the generative language large-scale interface determines that the second network traffic contains fourth network traffic of an attack, blocking the fourth network traffic;

[0043] When the rule matching module determines that the first network traffic or the generative language large-scale interface determines that the third network traffic contains a fifth network traffic of attack, the fifth network traffic is blocked.

[0044] Compared with the prior art, the flow adaptive security protection method provided by the embodiment can distinguish normal business flow from abnormal attack flow by setting a flow baseline model, reduce the detection amount of the generative language large-scale interface, improve the detection performance, and at the same time, the generative language large-scale interface is introduced for judgment, the number of rules is reduced, the accuracy of rule judgment is improved, and the efficiency of attack detection is improved.

[0045] It should be noted that ChatGPT is a generative language large model trained by OpenAI, which can be used for natural language processing tasks such as answering questions, generating text and speech recognition. It is based on the Transformer model structure and uses a large amount of language data for pre-training, which can be used to generate human-like natural language responses.

[0046] IPS: is the abbreviation of Intrusion Prevention System, which is a security device used to protect networks from unauthorized access and malicious attacks. IPS can monitor network traffic and automatically block attacks or take other measures to protect network security when potential attacks or vulnerabilities are detected.

[0047] Webshell: is executable code left on a website by an attacker, usually used to execute malicious instructions of the attacker.

[0048] Figure 2 The flow adaptive security protection method provided by the embodiment system architecture diagram, in some embodiments of the present application, the flow baseline model is used to detect the flow data of the external network accessing the internal network.

[0049] In some embodiments of the present application, the flow baseline model assigns second network flow smaller than the preset flow in the matchable network flow to the generative language large-scale interface, including:

[0050] The flow baseline model assigns second network flow with a rate greater than a preset rate to the generative language large-scale interface when an external network IP accesses a protected URL in the internal network;

[0051] The flow baseline model determines the external network flow accessing a non-existent resource in the internal network as second network flow, and assigns the second network flow to the generative language large-scale interface;

[0052] The flow baseline model determines the external network flow with an IP accessing the internal network with a single digit as second network flow, and assigns the second network flow to the generative language large-scale interface.

[0053] In specific embodiments of the present application, the traffic baseline model mainly serves to distinguish normal traffic from possible abnormal traffic. In general, attack traffic accounts for a very small proportion, except for flooding attacks such as DDoS. The traffic baseline model is used to let most normal traffic directly pass through the original rule matching, and a small part of uncertain traffic pass through the generative language model interface for attack judgment, so as to avoid the slow judgment of the large model interface, and has practical value.

[0054] The traffic baseline model has the following characteristics:

[0055] Adaptability: The traffic baseline records the traffic of normal business for a period of time, records and analyzes specific traffic indicators, sets upper and lower limits, and continuously monitors the traffic in the future to adjust the indicator values, achieving adaptive effect.

[0056] Judgment: The indicator conditions of the traffic baseline need to be specific quantitative values, so that there is a clear judgment of whether the conditions are met.

[0057] High efficiency: The calculation of the traffic baseline indicators needs to be simple and feasible, and should not occupy a large amount of computing power.

[0058] Adaptability: The traffic baseline records the traffic of normal business for a period of time, records and analyzes specific traffic indicators, sets upper and lower limits, and continuously monitors the traffic in the future to adjust the indicator values, achieving adaptive effect.

[0059] Judgment: The indicator conditions of the traffic baseline need to be specific quantitative values, so that there is a clear judgment of whether the conditions are met.

[0060] The specific indicators of the traffic baseline model include:

[0061] Access direction: external network to internal network, internal network to external network, and internal network to internal network, the direction that needs to be protected is mainly external network to internal network.

[0062] Single external network IP access rate: according to the actual business situation, record the access rate of single external network IP to the protected URL, set an upper and lower limit range, and if it exceeds the range, it is outside the baseline.

[0063] Path range of protected URL: according to the actual business situation, record the parameter name, value, path and other basic information of the URL to form a list, and if the access exceeds this list, it is outside the baseline.

[0064] Single-page access IP count: Generally, normal business will have different IPs accessing each URL, while the webshell used by attackers is often accessed only by the attacker, so the IP count of a URL access can be recorded. When a URL is accessed by only one IP or a few IPs, it is outside the baseline.

[0065] In some embodiments of the application, the generative language large-scale interface is a CHATGPT interface.

[0066] In specific embodiments of the application, the rule engine groups traffic according to sessions, and messages in the same group are generally request responses of the same quintuple. The rule engine will disassemble the traffic according to the protocol level until all fields are parsed. The rule engine will extract the clear text request in the application layer as the content to be detected. The generative language large model judgment interface identifies and judges the request content to achieve the effect of detecting attacks.

[0067] ChatGPT returns a clear conclusion of whether there is an attack behavior and a behavior description, which completes an attack judgment.

[0068] In some embodiments of the application, the method further includes marking the blocked traffic to obtain marked traffic, and introducing the marked traffic into a rule matching module or a generative language large-scale interface according to the state of the marked traffic.

[0069] In some embodiments of the application, introducing the marked traffic into a rule matching module or a generative language large-scale interface according to the state of the marked traffic for attack detection includes:

[0070] When the state of the marked traffic is normal, introducing the marked traffic into the rule matching module for attack detection;

[0071] When the state of the marked traffic is abnormal, introducing the marked traffic into the generative language large-scale interface for attack detection.

[0072] In specific embodiments of the application, the traffic marking module is mainly responsible for feedback marking of blocked traffic, and then marking the traffic quintuple with a mark bit. After being passed to the generative language large model interface, if the detection is an attack, it is marked as: abnormal, blocked. Then the subsequent session of the quintuple is directly marked as outside the baseline, and the newly created session of the quintuple enters the generative language large model interface again for attack judgment. If the detection is not an attack after being passed to the generative language large model interface, it is marked as normal, and then it is passed. Therefore, the subsequent messages of the quintuple session can be directly matched with the rules.

[0073] In order to better implement the method for adaptive security protection of traffic, on the basis of the method for adaptive security protection of traffic, as shown in Figure 3 The embodiment of the present application also provides a device for adaptive security protection of traffic, and the device for adaptive security protection of traffic 300 comprises:

[0074] A first module 301 is configured to acquire real-time network traffic and analyze the real-time network traffic to obtain matchable network traffic.

[0075] A second module 302 is configured to input the matchable network traffic into a traffic baseline model, distribute first network traffic greater than a preset traffic in the matchable network traffic to a rule matching module based on the traffic baseline model, and distribute second network traffic less than the preset traffic in the matchable network traffic to a large-scale interface of a generative language.

[0076] A third module 303 is configured to, when the large-scale interface of the generative language determines that third network traffic in the second network traffic does not exist attack, guide the third network traffic into the rule matching module.

[0077] A fourth module 304 is configured to, when the large-scale interface of the generative language determines that fourth network traffic in the second network traffic exists attack, block the fourth network traffic.

[0078] A fifth module 305 is configured to, when the rule matching module determines that the first network traffic or the large-scale interface of the generative language determines that fifth network traffic in the third network traffic exists attack, block the fifth network traffic.

[0079] The device for adaptive security protection of traffic 300 provided by the above embodiment can implement the technical solutions described in the method for adaptive security protection of traffic, and the principles of the implementation of the above modules or units can be referred to the corresponding content in the method for adaptive security protection of traffic, which will not be described here.

[0080] As shown in Figure 4 The present application also provides an electronic device 400. The electronic device 400 comprises a processor 401, a memory 402 and a display 403. Figure 4 Only part of the components of the electronic device 400 are shown, but it should be understood that all the shown components are not required to be implemented, and more or less components can be alternatively implemented.

[0081] The processor 401 may, in some embodiments, be a central processing unit (CPU), a microprocessor, or other data processing chip, for running program codes stored in the memory 402 or processing data, such as a flow adaptive security protection method in the present application.

[0082] In some embodiments, the processor 401 can be a single server or a group of servers. The group of servers can be centralized or distributed. In some embodiments, the processor 401 can be local or remote. In some embodiments, the processor 401 can be implemented in a cloud platform. In an embodiment, the cloud platform can include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an inter-organizational cloud, a multi-cloud, or the like, or any combination thereof.

[0083] The memory 402 may, in some embodiments, be an internal storage unit of the electronic device 400, such as a hard disk or a memory of the electronic device 400. In other embodiments, the memory 402 can also be an external storage device of the electronic device 400, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, or the like, equipped on the electronic device 400.

[0084] Further, the memory 403 can include both an internal storage unit and an external storage device of the electronic device 400. The memory 402 is used to store application software installed on the electronic device 400 and various types of data.

[0085] The display 403 may, in some embodiments, be an LED display, a liquid crystal display, a touch liquid crystal display, an OLED (Organic Light-Emitting Diode) touch, or the like. The display 403 is used to display information of the electronic device 400 and to display a visualized user interface. The components 401-403 of the electronic device 400 communicate with each other through a system bus.

[0086] In an embodiment, when the processor 401 executes a flow adaptive security protection program in the memory 402, the following steps can be implemented:

[0087] Obtaining real-time network traffic and parsing the real-time network traffic to obtain matchable network traffic;

[0088] input the matchable network traffic into a traffic baseline model, assign first network traffic greater than a preset traffic in the matchable network traffic to a rule matching module and assign second network traffic less than the preset traffic in the matchable network traffic to a generative language large-scale interface based on the traffic baseline model;

[0089] when the generative language large-scale interface determines that third network traffic in the second network traffic does not exist attack, guide the third network traffic into the rule matching module;

[0090] when the generative language large-scale interface determines that fourth network traffic in the second network traffic exists attack, block the fourth network traffic;

[0091] when the rule matching module determines that the first network traffic or the generative language large-scale interface determines that fifth network traffic in the third network traffic exists attack, block the fifth network traffic.

[0092] It should be understood that, in addition to the above functions, the processor 401 can also implement other functions when executing the traffic adaptive security protection program in the memory 402, which can be specifically understood in the description of the corresponding method embodiments.

[0093] Further, the type of the electronic device 400 is not specifically limited, and the electronic device 400 can be a mobile phone, a tablet computer, a personal digital assistant (PDA), a wearable device, a laptop, or the like. Exemplary embodiments of the portable electronic device include, but are not limited to, a portable electronic device running an IOS, an android, a microsoft, or other operating system. The above-mentioned portable electronic device can also be other portable electronic devices, such as a laptop having a touch-sensitive surface (e.g., a touch panel). It should also be understood that in some other embodiments of the present application, the electronic device 400 can also be a desktop computer having a touch-sensitive surface (e.g., a touch panel).

[0094] Those skilled in the art can understand that all or part of the processes of the above-mentioned embodiments can be completed by a computer program instructing related hardware, and the program can be stored in a computer readable storage medium. The computer readable storage medium includes a magnetic disk, an optical disk, a read-only memory, a random access memory, and the like.

[0095] The above merely describes preferred specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application.

Claims

1. A traffic adaptive security protection method, characterized in that: include: Obtaining real-time network traffic, and parsing the real-time network traffic to obtain matching network traffic; Inputting the matchable network traffic into a traffic baseline model, allocating a first network traffic greater than a preset traffic volume in the matchable network traffic to a rule matching module based on the traffic baseline model, and allocating a second network traffic less than the preset traffic volume in the matchable network traffic to a generative language large-scale interface; When the generative language large-scale interface determines that there is no third network traffic of the attack in the second network traffic, importing the third network traffic into a rule matching module; When the generative language large-scale interface determines that there is fourth network traffic of attack in the second network traffic, blocking the fourth network traffic; When the rule matching module determines that the first network traffic or the generative language large-scale interface determines that the third network traffic contains a fifth network traffic of attack, the fifth network traffic is blocked.

2. A flow adaptive security protection method according to claim 1, characterized in that: The traffic baseline model is used to detect traffic data of external network access to internal network.

3. A flow adaptive security protection method according to claim 1, characterized in that: The traffic baseline model distributes a second network flow that is smaller than the preset flow in the matchable network flow to the generative language large-scale interface, including: The traffic baseline model distributes the second network traffic whose rate of accessing the protected URL in the intranet from the external network IP is greater than the preset rate to the generative language large-scale interface; The traffic baseline model determines the external network traffic that accesses resources that do not exist in the internal network as the second network traffic, and allocates the second network traffic to the generative language large-scale interface; The traffic baseline model determines the external network traffic with a single-digit IP count of accessing the internal network from the external network as the second network traffic, and distributes the second network traffic to the generative language large-scale interface.

4. A flow adaptive security protection method according to claim 1, characterized in that: The generative language large-scale interface is obtained by calling the CHATGPT interface.

5. The flow adaptive security protection method according to claim 1, characterized in that: Also includes: The blocked traffic is marked to obtain marked traffic, and the marked traffic is introduced into a rule matching module or a generative language large-scale interface for attack detection according to a state of the marked traffic.

6. A flow adaptive security protection method according to claim 5, characterized in that: The step of importing the marked traffic into a rule matching module or a generative language large-scale interface for attack detection according to the state of the marked traffic includes: When the state of the marked traffic is normal, importing the marked traffic into a rule matching module for attack detection; When the state of the marked traffic is abnormal, the marked traffic is imported into a generative language large-scale interface for attack detection.

7. A flow-adaptive security protection method and device, characterized in that: include: The first module is used to obtain real-time network traffic and parse the real-time network traffic to obtain matching network traffic; A second module is configured to input the matchable network traffic into a traffic baseline model, allocate a first network traffic greater than a preset traffic flow in the matchable network traffic to a rule matching module based on the traffic baseline model, and allocate a second network traffic less than the preset traffic flow in the matchable network traffic to a generative language large-scale interface; a third module, configured to import the third network traffic into a rule matching module when the generative language large-scale interface determines that there is no third network traffic of attack in the second network traffic; A fourth module is configured to block the fourth network traffic when the generative language large-scale interface determines that there is a fourth network traffic of attack in the second network traffic; The fifth module is configured to block the fifth network traffic when the rule matching module determines that the first network traffic or the generative language large-scale interface determines that the third network traffic contains a fifth network traffic that is an attack.

8. The flow-adaptive safety protection device according to claim 7, characterized in that: The traffic baseline model is used to detect traffic data of external network access to internal network.

9. An electronic device, characterized in that: comprising a memory and a processor, wherein, The memory is used to store programs; The processor is coupled to the memory and is used to execute the program stored in the memory to implement the steps in the traffic adaptive security protection method described in any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that Used to store computer-readable programs or instructions, which, when executed by a processor, can implement the steps of a traffic adaptive security protection method as described in any one of claims 1 to 6 above.

Citation Information

Patent Citations

  • Joint modeling method for spoken language understanding model and language model and dialogue method

    CN108962224A

  • Network attack detection method and device

    CN112822187A