Method and apparatus for generating a malicious scan coping strategy

By generating a model with pre-defined response strategies, and calculating response strategies for network traffic data based on malicious scanning datasets, the problem of low generation efficiency in existing technologies is solved, achieving efficient and accurate generation of malicious scanning response strategies and enhancing network security.

CN117527315BActive Publication Date: 2026-08-25XIAN SECLOVER INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311376978.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-23
Publication Date
2026-08-25
Estimated Expiration
2043-10-23

AI Technical Summary

Technical Problem

Existing technologies cannot automatically generate effective malicious scanning countermeasures, resulting in low generation efficiency.

Method used

By generating a model based on a pre-trained preset response strategy, and using a malicious scanning dataset, the model directly calculates the current network traffic data to generate the target response strategy, including the judgment result, credibility, scanning category, scanning sub-category and degree of harm, calculates the harm score, and generates the response strategy based on the comparison results.

Benefits of technology

It improves the accuracy and efficiency of generating malicious scanning response strategies, can dynamically respond to common attacks, has strong model generalization ability, and enhances network security and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117527315B_ABST
    Figure CN117527315B_ABST
Patent Text Reader

Abstract

The application discloses a malicious scanning coping strategy generation method and device, the method comprises the following steps: obtaining current network flow data, inputting the current network flow data into a preset coping strategy generation model for calculation, and generating a target coping strategy corresponding to the current network flow data. According to the scheme, the preset coping strategy generation model is directly used to calculate the current network flow data, and the corresponding target coping strategy can be obtained, so that the accuracy and efficiency of generating the target coping strategy are improved. In addition, since the preset coping strategy generation model is obtained based on a preset coping strategy model, the target coping strategy can be dynamically generated for all common attacks through the preset coping strategy model, the generalization ability of the model is strong, and the accuracy of generating the target coping strategy is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method and apparatus for generating malicious scanning response strategies. Background Technology

[0002] With the continuous development of computer network technology, network security issues are receiving increasing attention. Malicious scanning, as a form of network attack, has a significant impact on network security. Therefore, addressing malicious scanning helps in the early detection of threats, enhances network security, reduces attack costs, and optimizes network performance, thereby maintaining network stability and data security.

[0003] In related technologies, malicious scans are detected and identified through various simulation tools, open-source scanning tools, and security testing platforms, and then the malicious scans are processed manually. It is impossible to automatically generate corresponding strategies to deal with the malicious scans.

[0004] Therefore, using existing technologies results in low efficiency in generating malicious scanning response strategies. Summary of the Invention

[0005] This invention aims to at least solve the technical problems existing in the prior art. To this end, the first aspect of this invention proposes a method for generating a malicious scanning countermeasure strategy, the method comprising:

[0006] Get current network traffic data;

[0007] The current network traffic data is input into the preset response strategy generation model for calculation, generating a target response strategy corresponding to the current network traffic data; wherein, the preset response strategy generation model is obtained based on the preset response strategy model, which is pre-trained based on the malicious scanning dataset.

[0008] In one possible implementation, current network traffic data is input into a preset response strategy generation model for calculation, generating a target response strategy corresponding to the current network traffic data, including:

[0009] Input the current network traffic data into the preset response strategy generation model, and calculate the target response strategy value corresponding to the current network traffic data through the preset response strategy model in the preset response strategy generation model;

[0010] The target response strategy value is compared with the preset response strategy value, and a comparison result is generated.

[0011] Based on the comparison results and the correspondence between the preset response strategy value and the preset response strategy, a target response strategy corresponding to the current network traffic data is generated.

[0012] In one possible implementation, current network traffic data is input into a preset response strategy generation model, and a target response strategy value corresponding to the current network traffic data is calculated using a preset response strategy model within the preset response strategy generation model, including:

[0013] The current network traffic data is input into the preset response strategy generation model to generate a judgment result, credibility, scan category, scan subcategory, and severity corresponding to the current network traffic data; among which, the judgment result is used to characterize whether the current network traffic data is scan data;

[0014] If the current network traffic data is determined to be scanned data based on the judgment result, then the hazard score corresponding to the current network traffic data is calculated based on the credibility, scan category, scan subcategory, and degree of harm.

[0015] Calculate the target response strategy value based on the hazard score.

[0016] In one possible implementation, the hazard score includes a first hazard score, a second hazard score, and a third hazard score. The hazard score corresponding to the current network traffic data is calculated based on credibility, scan category, scan subcategory, and hazard severity, including:

[0017] Based on credibility and severity, calculate the first hazard score corresponding to the current network traffic data;

[0018] Based on the first hazard score, the scan sub-category, and the scan major category, calculate the second hazard score corresponding to the current network traffic data;

[0019] Based on the second hazard score, the scan sub-category, and the scan major category, calculate the third hazard score corresponding to the current network traffic data.

[0020] In one possible implementation, based on the comparison results, the correspondence between preset response strategy values ​​and preset response strategies, a target response strategy corresponding to the current network traffic data is generated, including:

[0021] If the target response strategy value is determined to reach the preset response strategy value based on the comparison results, then the preset response strategy corresponding to the preset response strategy value will be used as the target response strategy according to the correspondence between the preset response strategy value and the preset response strategy.

[0022] In one possible implementation, the process of constructing a pre-defined response strategy model includes:

[0023] Obtain the malicious scan dataset; the malicious scan dataset includes the basic attribute information, credibility, scan category, scan subcategory, and degree of harm of each malicious scan data;

[0024] The malicious scanning dataset is input into the initial response strategy model for training, generating a preset response strategy model.

[0025] In one possible implementation, the malicious scanning dataset is input into an initial response strategy model for training to generate a preset response strategy model, including:

[0026] The malicious scanning dataset is input into the initial response strategy model for training, generating an intermediate response strategy model;

[0027] The intermediate response strategy model is encapsulated and parameterized to generate a preset response strategy model.

[0028] A second aspect of the present invention provides an apparatus for generating a malicious scanning response strategy, the apparatus comprising:

[0029] The acquisition module is used to acquire current network traffic data;

[0030] The generation module is used to input the current network traffic data into the preset response strategy generation model for calculation, and generate the target response strategy corresponding to the current network traffic data; wherein, the preset response strategy generation model is obtained based on the preset response strategy model, which is pre-trained based on the malicious scanning dataset.

[0031] In one possible implementation, the above-mentioned generation module is specifically used for:

[0032] Input the current network traffic data into the preset response strategy generation model, and calculate the target response strategy value corresponding to the current network traffic data through the preset response strategy model in the preset response strategy generation model;

[0033] The target response strategy value is compared with the preset response strategy value, and a comparison result is generated.

[0034] Based on the comparison results and the correspondence between the preset response strategy value and the preset response strategy, a target response strategy corresponding to the current network traffic data is generated.

[0035] In one possible implementation, the above-described generation module is further configured to:

[0036] The current network traffic data is input into the preset response strategy generation model to generate a judgment result, credibility, scan category, scan subcategory, and severity corresponding to the current network traffic data; among which, the judgment result is used to characterize whether the current network traffic data is scan data;

[0037] If the current network traffic data is determined to be scanned data based on the judgment result, then the hazard score corresponding to the current network traffic data is calculated based on the credibility, scan category, scan subcategory, and degree of harm.

[0038] Calculate the target response strategy value based on the hazard score.

[0039] In one possible implementation, the hazard score includes a first hazard score, a second hazard score, and a third hazard score, and the aforementioned generation module is further configured to:

[0040] Based on credibility and severity, calculate the first hazard score corresponding to the current network traffic data;

[0041] Based on the first hazard score, the scan sub-category, and the scan major category, calculate the second hazard score corresponding to the current network traffic data;

[0042] Based on the second hazard score, the scan sub-category, and the scan major category, calculate the third hazard score corresponding to the current network traffic data.

[0043] In one possible implementation, the above-described generation module is further configured to:

[0044] If the target response strategy value is determined to reach the preset response strategy value based on the comparison results, then the preset response strategy corresponding to the preset response strategy value will be used as the target response strategy according to the correspondence between the preset response strategy value and the preset response strategy.

[0045] In one possible implementation, the apparatus for generating the malicious scanning response strategy described above is further used to:

[0046] Obtain the malicious scan dataset; the malicious scan dataset includes the basic attribute information, credibility, scan category, scan subcategory, and degree of harm of each malicious scan data;

[0047] The malicious scanning dataset is input into the initial response strategy model for training, generating a preset response strategy model.

[0048] In one possible implementation, the apparatus for generating the malicious scanning response strategy described above is further used to:

[0049] The malicious scanning dataset is input into the initial response strategy model for training, generating an intermediate response strategy model;

[0050] The intermediate response strategy model is encapsulated and parameterized to generate a preset response strategy model.

[0051] A third aspect of the present invention provides an electronic device comprising a processor and a memory, wherein the memory stores at least one instruction, at least one program, a code set, or an instruction set, wherein the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the method for generating a malicious scanning response strategy as described in the first aspect.

[0052] A fourth aspect of the present invention provides a computer-readable storage medium storing at least one instruction, at least one program, a code set, or an instruction set, wherein the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by a processor to implement the method for generating a malicious scanning response strategy as described in the first aspect.

[0053] The embodiments of this application have the following beneficial effects:

[0054] This application provides a method for generating malicious scanning response strategies. The method includes: acquiring current network traffic data; inputting the current network traffic data into a preset response strategy generation model for calculation, generating a target response strategy corresponding to the current network traffic data; wherein the preset response strategy generation model is obtained based on a preset response strategy model, which is pre-trained based on a malicious scanning dataset. This solution directly calculates the current network traffic data using a pre-trained preset response strategy generation model, thus obtaining the corresponding target response strategy, improving the accuracy and efficiency of generating the target response strategy. Furthermore, since the preset response strategy generation model is based on a preset response strategy model, it can dynamically generate target response strategies for all common attacks, exhibiting strong generalization ability and further improving the accuracy of generating the target response strategy. Attached Figure Description

[0055] Figure 1 A block diagram of a computer device provided in an embodiment of this application;

[0056] Figure 2 A flowchart illustrating the steps of a method for generating a malicious scanning response strategy as provided in this application embodiment;

[0057] Figure 3 A flowchart illustrating the steps for constructing a preset response strategy model, as provided in this embodiment of the invention;

[0058] Figure 4 A flowchart illustrating the steps for generating a target response strategy is provided in an embodiment of the present invention.

[0059] Figure 5 A flowchart illustrating the steps for calculating a target response strategy value, provided in an embodiment of the present invention;

[0060] Figure 6 This is a structural block diagram of the apparatus for generating a malicious scanning response strategy provided in an embodiment of this application. Detailed Implementation

[0061] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0062] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of embodiments of this disclosure, unless otherwise stated, "a plurality of" means two or more. Furthermore, the use of "based on" or "according to" implies openness and inclusiveness, because processes, steps, calculations, or other actions "based on" or "according to" one or more of the stated conditions or values ​​may in practice be based on additional conditions or beyond the stated values.

[0063] The method for generating malicious scanning response strategies provided in this application can be applied to computer devices (electronic devices). The computer device can be a server or a terminal. The server can be a single server or a server cluster composed of multiple servers. This application does not specifically limit this. The terminal can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices.

[0064] Taking a computer device as an example, Figure 1 A block diagram of a server is shown, such as Figure 1 As shown, the server may include a processor and memory connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. When the computer program is executed by the processor, it implements a method for generating a malicious scanning response strategy.

[0065] Those skilled in the art will understand that Figure 1 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the server to which the present application is applied. Optionally, the server may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0066] It should be noted that the execution subject of the embodiments of this application can be a computer device or a malicious scanning response strategy generation device. The following method embodiments will be described with a computer device as the execution subject.

[0067] Figure 2 A flowchart illustrating the steps of a method for generating a malicious scanning countermeasure strategy provided in an embodiment of this application. Figure 2 As shown, the method includes the following steps:

[0068] Step 202: Obtain current network traffic data.

[0069] With the continuous development of computer network technology, network security issues are receiving increasing attention. Malicious scanning, as a form of network attack, has a significant impact on network security. Therefore, addressing malicious scanning helps in the early detection of threats, enhances network security, reduces attack costs, and optimizes network performance, thereby maintaining network stability and data security.

[0070] When generating a malicious scanning response strategy, it is necessary to first obtain current network traffic data, which may include multiple data entries. Current network traffic data can be obtained by capturing traffic packets using a packet capture tool, or by obtaining detailed network log information using a network log tool. Of course, other methods can also be used to obtain current network traffic data; this application embodiment does not specifically limit the methods used.

[0071] Step 204: Input the current network traffic data into the preset response strategy generation model for calculation, and generate the target response strategy corresponding to the current network traffic data.

[0072] Among them, the preset response strategy generation model is obtained based on the preset response strategy model, which is pre-trained based on the malicious scanning dataset. After obtaining the current network traffic data, the current network traffic data can be input into the preset response strategy generation model for calculation, thereby generating the target response strategy corresponding to the current network traffic data.

[0073] The target response strategy is the response strategy when the current network traffic data is scanned data. In addition, if the current network traffic data is non-malicious scanned data, the generated target response strategy can be empty, that is, it will not contain any response strategy.

[0074] Conversely, if the current network traffic data is malicious scanning data, then a corresponding targeted response strategy can be generated, which includes specific response measures. It should also be noted that this targeted response strategy can include only one response measure or a combination of multiple response measures.

[0075] The preset response strategy generation model is a model used to dynamically generate target response strategies based on preset response strategy models. The construction process of this model is as follows: Figure 3 As shown, Figure 3 A flowchart illustrating the steps for constructing a preset response strategy model, as provided in this embodiment of the invention, includes:

[0076] Step 302: Obtain the malicious scanning dataset.

[0077] Before building the pre-defined response strategy model, a data preparation process is required. Specifically, a malicious scanning dataset can be collected first. The amount of data in this malicious scanning dataset needs to be sufficient, for example, no less than 100,000 malicious scanning data.

[0078] In addition, the malicious scanning dataset can include basic attribute information, credibility, scanning category, scanning sub-category, and severity of each malicious scan. The basic attribute information is the inherent characteristic information of the malicious scan data itself and does not require further processing or analysis. Credibility, scanning category, scanning sub-category, and severity are characteristic information that requires processing and analysis to obtain.

[0079] Credibility can be expressed as a percentage, representing the probability that the malicious scan data belongs to the corresponding scan type, or scan sub-category. A higher credibility value indicates a greater likelihood of it being that scan type. Scan categories can include, but are not limited to, discovery and detection, port scanning, service and operating system identification, vulnerability scanning, malicious activity and intrusion detection, stealth scanning, and competing scans. Scan sub-categories are the scan types belonging to each scan category. For example, for the scan category of port scanning, the corresponding scan sub-categories can include, but are not limited to, TCP port scanning, UDP port scanning, ACK scanning, Windows scanning, and FTP Bounce scanning. The severity can also be expressed as a percentage, representing the overall harm that the malicious scan data may cause to the system, business, or resources. Typically, this severity value can be obtained through comprehensive calculation by specific detection equipment or models.

[0080] Next, the malicious scanning data in the malicious scanning dataset can be preprocessed. The data preprocessing process may include, but is not limited to, cleaning, deduplication, encoding, unifying units, and noise reduction.

[0081] After labeling the pre-processed malicious scan dataset, security experts can compile a set of all possible countermeasures and combinations thereof by combining all malicious scanning behaviors, thus obtaining a pre-defined countermeasure set. Examples include intrusion re-detection, firewall blocking, port or service filtering, IP blocking, blacklisting, network alerts, network monitoring, logging, enhanced authentication, network isolation, and reassessment, or combinations thereof. Then, based on the malicious scan data, and according to the actual scenario and experience, security experts can provide the most appropriate pre-defined countermeasure from the above strategies or combinations thereof.

[0082] Next, assume that the [confidence, scan category, scan subcategory, severity] in the malicious scan dataset after data annotation correspond to [r, k, m, d] respectively. First, for each malicious scan data, the first severity score s1 can be calculated using formula (1). Then, the second severity score s2 can be calculated using formula (2), which is the same-family severity score. Finally, the third severity score s3 can be calculated using formula (3), which is the comprehensive severity score.

[0083] s1=a1*r*d+b1 (1)

[0084] s2=a2*(s1*j) / t+b2 (2)

[0085] s3=a3*(s2*7 / s01+ s2 / s02)+b3 (3)

[0086] Where a1, a2, and a3 represent the sensitivity of variables under each hazard score, and b1, b2, and b3 represent the offset under each hazard score. a1, a2, a3, b1, b2, and b3 are all fixed values ​​at model creation and can be determined by engineers based on actual modeling experience and real-world scenarios during model creation, and optimized and adjusted during subsequent model training. j represents the actual number of malicious scans belonging to the same scan subclass in the malicious scan dataset. For example, for the TCP port scan subclass, if there are 10,000 malicious scans in the dataset, then j is 10,000. t represents the total number of malicious scans belonging to the same scan major class in the malicious scan dataset. For example, for the port scan major class, if the TCP port scan subclass has 10,000 entries, the UDP port scan subclass has 20 entries, and the Windows scan subclass has 68 entries, then t is 10,000 + 20 + 68 = 10,088. s01 and s02 represent the average harm scores of the current malicious scan data within the malicious scan dataset for the past 24 hours, corresponding to the same sub-class and the same major class of scans. Specifically, s01 = avg(s_small), which is the arithmetic mean of the harm scores of all sub-classes within the same malicious scan data over the past 24 hours. s02 = avg(s_major), which is the arithmetic mean of the harm scores of all major classes within the same malicious scan data over the past 24 hours.

[0087] Then, the target response strategy value can be calculated based on the first hazard score, the second hazard score and the third hazard score. Specifically, the target response strategy value y can be calculated according to formula (4).

[0088] y=n1*s1+n2*s2+n3*s3+b4 (4)

[0089] Among them, n1, n2, n3 and b4 are model parameters of the preset response strategy model, which are initially fixed values ​​and will be determined in the subsequent training and adjustment stages.

[0090] The corresponding target response strategy can be determined based on the target response strategy value. Optionally, when the target response strategy value reaches the preset response strategy value, the corresponding target response strategy can be determined from the preset response strategy. That is, the preset response strategy value and the preset response strategy have a pre-set correspondence.

[0091] Step 304: Input the malicious scanning dataset into the initial response strategy model for training to generate the preset response strategy model.

[0092] The input to the preset response strategy model is the malicious scan dataset after data annotation, and the output is the target response strategy corresponding to each malicious scan. The malicious scan dataset can then be input into the initial response strategy model for training. The training rules are the same as those used to generate target response strategy values ​​and determine the target response strategies. By comparing the training output with the data annotation results, the model is trained and evaluated, and its parameters are gradually adjusted and optimized until the preset accuracy is achieved, thus generating the final preset response strategy model.

[0093] In this embodiment, the accuracy of the preset response strategy model is improved by using training and evaluation to construct the preset response strategy model. In addition, the preset response strategy model can dynamically generate target response strategies for all common attacks, and the model has strong generalization ability.

[0094] In some alternative embodiments, the malicious scanning dataset can be first input into the initial response strategy model for training to generate an intermediate response strategy model. Then, the intermediate response strategy model can be encapsulated and parameterized to generate a preset response strategy model.

[0095] In encapsulating and parameterizing intermediate response strategy models, the model's definition and hierarchical structure are typically encapsulated within a class or function. This makes the model structure clearer and facilitates modification and reuse. Furthermore, by using key model parameters, such as the number of layers, hidden units, and activation functions as input parameters to the class or function, these parameters can be flexibly adjusted during model instantiation. This helps reuse the same model structure across different tasks or datasets and facilitates hyperparameter search or model tuning. It may also include encapsulation of input / output data formats and exception handling. This encapsulation and parameterization process makes the model more modular, flexible, and maintainable, thus making it easier to handle different tasks, datasets, and experimental settings, and improving the robustness of the pre-defined response strategy model.

[0096] Therefore, correspondingly, when inputting current network traffic data into the preset response strategy generation model for calculation, such as Figure 4 As shown, Figure 4 A flowchart illustrating the steps for generating a target response strategy, as provided in this embodiment of the invention, includes:

[0097] Step 402: Input the current network traffic data into the preset response strategy generation model, and calculate the target response strategy value corresponding to the current network traffic data through the preset response strategy model in the preset response strategy generation model.

[0098] Step 404: Compare the target response strategy value with the preset response strategy value and generate a comparison result.

[0099] Step 406: Based on the comparison results and the correspondence between the preset response strategy value and the preset response strategy, generate the target response strategy corresponding to the current network traffic data.

[0100] After obtaining the current network traffic data, optionally, the network traffic data can be standardized first, including but not limited to noise reduction, dimensionless removal, and removal of special characters. Then, the current network traffic data is input into a preset response strategy generation model, which calculates the target response strategy value corresponding to the current network traffic data using a preset response strategy model.

[0101] Optionally, such as Figure 5 As shown, Figure 5 A flowchart illustrating the steps for calculating a target response strategy value, provided in an embodiment of the present invention, includes:

[0102] Step 502: Input the current network traffic data into the preset response strategy generation model to generate the judgment result, credibility, scanning category, scanning sub-category, and degree of harm corresponding to the current network traffic data.

[0103] Step 504: If the current network traffic data is determined to be scanned data based on the judgment result, then calculate the hazard score corresponding to the current network traffic data based on the credibility, scan category, scan subcategory, and degree of hazard.

[0104] Step 506: Calculate the target response strategy value based on the hazard score.

[0105] The judgment result is used to characterize whether the current network traffic data is scanned data. This result can be obtained using proprietary equipment or a proprietary analysis model. If the judgment result determines that the current network traffic data is not scanned data, subsequent processes can be executed. For example, if the current network traffic data is a request, the subsequent request process can continue. Conversely, if the judgment result determines that the current network traffic data is scanned data, a hazard score corresponding to the current network traffic data is calculated based on credibility, scan category, scan subcategory, and severity. Based on the hazard score, the target response strategy value is calculated.

[0106] The credibility of current network traffic data can be expressed as a percentage. It represents the probability that the current network traffic data belongs to a specific scan type, or scan sub-category. The higher the credibility value, the greater the probability of it being that scan type. Scan categories can include, but are not limited to, discovery and detection, port scanning, operating system identification, vulnerability scanning, malicious activity and intrusion detection, stealth scanning, and contested scanning. Scan sub-categories are the scan types belonging to each scan category. For example, for the scan category of port scanning, the corresponding scan sub-categories can include, but are not limited to, TCP port scanning, UDP port scanning, ACK scanning, Windows scanning, and FTP Bounce scanning. The severity can also be expressed as a percentage. It represents the overall harm that the current network traffic data may cause to the system, services, or resources. Typically, this severity value can be obtained through comprehensive calculation by specific detection equipment or models.

[0107] Optionally, the hazard score may include a first hazard score, a second hazard score, and a third hazard score. When calculating the hazard score corresponding to the current network traffic data based on credibility, scan category, scan subcategory, and hazard level, the first hazard score corresponding to the current network traffic data may be calculated based on credibility and hazard level. Then, the second hazard score corresponding to the current network traffic data may be calculated based on the first hazard score, scan subcategory, and scan category. Finally, the third hazard score corresponding to the current network traffic data may be calculated based on the second hazard score, scan subcategory, and scan category.

[0108] The specific calculation process of the first hazard score, the second hazard score, and the third hazard score can be referred to the implementation process in the above embodiment of constructing a preset response strategy model, and will not be repeated here.

[0109] Next, the target response strategy value can be compared with the preset response strategy value to generate a comparison result. If the comparison result determines that the target response strategy value reaches the preset response strategy value, then according to the correspondence between the preset response strategy value and the preset response strategy, the preset response strategy corresponding to the preset response strategy value is taken as the target response strategy.

[0110] Ultimately, subsequent processes can be executed based on the target response strategy. Specifically, depending on the different business systems, corresponding business operations can be performed on the generated target response strategy. For example, if the generated target response strategy is IP blocking, the relevant logic for IP blocking can be executed automatically without manual intervention, thus enhancing the efficiency of subsequent handling based on the target response strategy. In addition, it enables comprehensive protection that can be combined with actual business scenarios, further enhancing the security of the system and data.

[0111] In this embodiment, the final target response strategy is determined by calculating different target response strategy values ​​and then determining the relationship between the target response strategy values ​​and the preset response strategy values. This method is simple and easy to operate, thereby improving the accuracy and efficiency of generating target response strategies. In addition, since highly targeted target response strategies can be generated in real time, the timeliness, efficiency and accuracy of generating target response strategies are improved.

[0112] This application provides a method for generating malicious scanning response strategies. The method includes: acquiring current network traffic data; inputting the current network traffic data into a preset response strategy generation model for calculation, generating a target response strategy corresponding to the current network traffic data; wherein the preset response strategy generation model is obtained based on a preset response strategy model, which is pre-trained based on a malicious scanning dataset. This solution directly calculates the current network traffic data using a pre-trained preset response strategy generation model, thus obtaining the corresponding target response strategy, improving the accuracy and efficiency of generating the target response strategy. Furthermore, since the preset response strategy generation model is based on a preset response strategy model, it can dynamically generate target response strategies for all common attacks, exhibiting strong generalization ability and further improving the accuracy of generating the target response strategy.

[0113] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0114] Figure 6 This is a structural block diagram of a device for generating a malicious scanning response strategy, provided in an embodiment of this application.

[0115] like Figure 6 As shown, the malicious scanning response strategy generation device 600 includes:

[0116] The acquisition module 602 is used to acquire current network traffic data.

[0117] The generation module 604 is used to input the current network traffic data of the model into the preset response strategy generation model for calculation, and generate the target response strategy corresponding to the current network traffic data of the model; wherein, the model preset response strategy generation model is obtained based on the preset response strategy model, and the preset response strategy model is pre-trained based on the malicious scanning dataset.

[0118] Regarding the apparatus in the above embodiments, the specific methods by which each module performs its operations have been described in detail in the embodiments related to the method, and will not be elaborated upon here. Each module in the above-described malicious scanning countermeasure generation apparatus can be implemented entirely or partially through software, hardware, or a combination thereof. Each module can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations of each module.

[0119] In one embodiment of this application, a computer device is provided, the computer device including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:

[0120] Get current network traffic data;

[0121] The current network traffic data is input into the preset response strategy generation model for calculation, generating a target response strategy corresponding to the current network traffic data; wherein, the preset response strategy generation model is obtained based on the preset response strategy model, which is pre-trained based on the malicious scanning dataset.

[0122] In one embodiment of this application, the processor further performs the following steps when executing the computer program:

[0123] Input the current network traffic data into the preset response strategy generation model, and calculate the target response strategy value corresponding to the current network traffic data through the preset response strategy model in the preset response strategy generation model;

[0124] The target response strategy value is compared with the preset response strategy value, and a comparison result is generated.

[0125] Based on the comparison results and the correspondence between the preset response strategy value and the preset response strategy, a target response strategy corresponding to the current network traffic data is generated.

[0126] In one embodiment of this application, the processor further performs the following steps when executing the computer program:

[0127] The current network traffic data is input into the preset response strategy generation model to generate a judgment result, credibility, scan category, scan subcategory, and severity corresponding to the current network traffic data; among which, the judgment result is used to characterize whether the current network traffic data is scan data;

[0128] If the current network traffic data is determined to be scanned data based on the judgment result, then the hazard score corresponding to the current network traffic data is calculated based on the credibility, scan category, scan subcategory, and degree of harm.

[0129] Calculate the target response strategy value based on the hazard score.

[0130] In one embodiment of this application, the hazard score includes a first hazard score, a second hazard score, and a third hazard score. When the processor executes the computer program, it further performs the following steps:

[0131] Based on credibility and severity, calculate the first hazard score corresponding to the current network traffic data;

[0132] Based on the first hazard score, the scan sub-category, and the scan major category, calculate the second hazard score corresponding to the current network traffic data;

[0133] Based on the second hazard score, the scan sub-category, and the scan major category, calculate the third hazard score corresponding to the current network traffic data.

[0134] In one embodiment of this application, the processor further performs the following steps when executing the computer program:

[0135] If the target response strategy value is determined to reach the preset response strategy value based on the comparison results, then the preset response strategy corresponding to the preset response strategy value will be used as the target response strategy according to the correspondence between the preset response strategy value and the preset response strategy.

[0136] In one embodiment of this application, the processor further performs the following steps when executing the computer program:

[0137] Obtain the malicious scan dataset; the malicious scan dataset includes the basic attribute information, credibility, scan category, scan subcategory, and degree of harm of each malicious scan data;

[0138] The malicious scanning dataset is input into the initial response strategy model for training, generating a preset response strategy model.

[0139] In one embodiment of this application, the processor further performs the following steps when executing the computer program:

[0140] The malicious scanning dataset is input into the initial response strategy model for training, generating an intermediate response strategy model;

[0141] The intermediate response strategy model is encapsulated and parameterized to generate a preset response strategy model.

[0142] The computer device provided in this application embodiment has a similar implementation principle and technical effect to the above method embodiment, and will not be described again here.

[0143] In one embodiment of this application, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, it performs the following steps:

[0144] Get current network traffic data;

[0145] The current network traffic data is input into the preset response strategy generation model for calculation, generating a target response strategy corresponding to the current network traffic data; wherein, the preset response strategy generation model is obtained based on the preset response strategy model, which is pre-trained based on the malicious scanning dataset.

[0146] In one embodiment of this application, the computer program, when executed by a processor, further performs the following steps:

[0147] Input the current network traffic data into the preset response strategy generation model, and calculate the target response strategy value corresponding to the current network traffic data through the preset response strategy model in the preset response strategy generation model;

[0148] The target response strategy value is compared with the preset response strategy value, and a comparison result is generated.

[0149] Based on the comparison results and the correspondence between the preset response strategy value and the preset response strategy, a target response strategy corresponding to the current network traffic data is generated.

[0150] In one embodiment of this application, the computer program, when executed by a processor, further performs the following steps:

[0151] The current network traffic data is input into the preset response strategy generation model to generate a judgment result, credibility, scan category, scan subcategory, and severity corresponding to the current network traffic data; among which, the judgment result is used to characterize whether the current network traffic data is scan data;

[0152] If the current network traffic data is determined to be scanned data based on the judgment result, then the hazard score corresponding to the current network traffic data is calculated based on the credibility, scan category, scan subcategory, and degree of harm.

[0153] Calculate the target response strategy value based on the hazard score.

[0154] In one embodiment of this application, the hazard score includes a first hazard score, a second hazard score, and a third hazard score. When the computer program is executed by the processor, it further performs the following steps:

[0155] Based on credibility and severity, calculate the first hazard score corresponding to the current network traffic data;

[0156] Based on the first hazard score, the scan sub-category, and the scan major category, calculate the second hazard score corresponding to the current network traffic data;

[0157] Based on the second hazard score, the scan sub-category, and the scan major category, calculate the third hazard score corresponding to the current network traffic data.

[0158] In one embodiment of this application, the computer program, when executed by a processor, further performs the following steps:

[0159] If the target response strategy value is determined to reach the preset response strategy value based on the comparison results, then the preset response strategy corresponding to the preset response strategy value will be used as the target response strategy according to the correspondence between the preset response strategy value and the preset response strategy.

[0160] In one embodiment of this application, the computer program, when executed by a processor, further performs the following steps:

[0161] Obtain the malicious scan dataset; the malicious scan dataset includes the basic attribute information, credibility, scan category, scan subcategory, and degree of harm of each malicious scan data;

[0162] The malicious scanning dataset is input into the initial response strategy model for training, generating a preset response strategy model.

[0163] In one embodiment of this application, the computer program, when executed by a processor, further performs the following steps:

[0164] The malicious scanning dataset is input into the initial response strategy model for training, generating an intermediate response strategy model;

[0165] The intermediate response strategy model is encapsulated and parameterized to generate a preset response strategy model.

[0166] The computer-readable storage medium provided in this embodiment is similar in principle and technical effect to the method embodiment described above, and will not be repeated here.

[0167] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.

[0168] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0169] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. A method for generating a malicious scanning response strategy, characterized in that, The method includes: Get current network traffic data; The current network traffic data is input into a preset response strategy generation model for calculation, generating a target response strategy corresponding to the current network traffic data, including: The current network traffic data is input into a preset response strategy generation model. The target response strategy value corresponding to the current network traffic data is calculated using the preset response strategy model within the preset response strategy generation model, including: The preset response strategy model calculates the judgment result, credibility, scan category, scan subcategory, and severity corresponding to the current network traffic data; wherein, the judgment result is used to characterize whether the current network traffic data is scanned data; if the judgment result determines that the current network traffic data is scanned data, then a severity score corresponding to the current network traffic data is calculated based on the credibility, scan category, scan subcategory, and severity; the severity score includes a first severity score, a second severity score, and a third severity score, and the calculation of the severity score corresponding to the current network traffic data based on the credibility, scan category, scan subcategory, and severity includes: Based on the credibility and the degree of harm, calculate the first harm score corresponding to the current network traffic data; based on the first harm score, the scan sub-category and the scan major category, calculate the second harm score corresponding to the current network traffic data; based on the second harm score, the scan sub-category and the scan major category, calculate the third harm score corresponding to the current network traffic data; based on the harm scores, calculate the target response strategy value. The target response strategy value is compared with the preset response strategy value to generate a comparison result. Based on the comparison results and the correspondence between the preset response strategy value and the preset response strategy, a target response strategy corresponding to the current network traffic data is generated; wherein, the preset response strategy generation model is obtained based on the preset response strategy model, and the preset response strategy model is pre-trained based on the malicious scanning dataset; the credibility is used to characterize the probability that the current network traffic data is a corresponding scanning subclass, and the scanning subclass is a scanning type belonging to each scanning major class.

2. The method according to claim 1, characterized in that, The step of generating a target response strategy corresponding to the current network traffic data based on the comparison result, the correspondence between the preset response strategy value and the preset response strategy, includes: If, based on the comparison result, it is determined that the target response strategy value reaches the preset response strategy value, then, according to the correspondence between the preset response strategy value and the preset response strategy, the preset response strategy corresponding to the preset response strategy value is taken as the target response strategy.

3. The method according to claim 1 or 2, characterized in that, The process of constructing the preset response strategy model includes: Obtain a malicious scanning dataset; wherein, the malicious scanning dataset includes basic attribute information, credibility, scanning category, scanning subcategory, and degree of harm corresponding to each malicious scanning data; The malicious scanning dataset is input into the initial response strategy model for training, thereby generating the preset response strategy model.

4. The method according to claim 3, characterized in that, The step of inputting the malicious scanning dataset into the initial response strategy model for training to generate the preset response strategy model includes: The malicious scanning dataset is input into the initial response strategy model for training, generating an intermediate response strategy model; The intermediate response strategy model is encapsulated and parameterized to generate the preset response strategy model.

5. A device for generating a malicious scanning response strategy, characterized in that, The device includes: The acquisition module is used to acquire current network traffic data; The generation module is used to input the current network traffic data into a preset response strategy generation model for calculation, generating a target response strategy corresponding to the current network traffic data. This includes: inputting the current network traffic data into the preset response strategy generation model, and calculating the target response strategy value corresponding to the current network traffic data using a preset response strategy model within the preset response strategy generation model. This includes: calculating the judgment result, credibility, scan category, scan subcategory, and severity level corresponding to the current network traffic data using the preset response strategy model. The judgment result is used to characterize whether the current network traffic data is scanned data. If the judgment result determines that the current network traffic data is scanned data, then a severity score corresponding to the current network traffic data is calculated based on the credibility, scan category, scan subcategory, and severity level. The severity score includes a first severity score, a second severity score, and a third severity score. The calculation of the target response strategy value corresponding to the current network traffic data based on the credibility, scan category, scan subcategory, and severity level... The hazard score includes: calculating a first hazard score corresponding to the current network traffic data based on the credibility and the degree of hazard; calculating a second hazard score corresponding to the current network traffic data based on the first hazard score, the scan sub-category, and the scan major category; calculating a third hazard score corresponding to the current network traffic data based on the second hazard score, the scan sub-category, and the scan major category; calculating a target response strategy value based on the hazard score; comparing the target response strategy value with a preset response strategy value to generate a comparison result; and generating a target response strategy corresponding to the current network traffic data based on the comparison result, the correspondence between the preset response strategy value and the preset response strategy; wherein the preset response strategy generation model is obtained based on a preset response strategy model, and the preset response strategy model is pre-trained based on a malicious scanning dataset; the credibility is used to characterize the probability that the current network traffic data belongs to the corresponding scan sub-category, and the scan sub-category is the scan type belonging to each scan major category.

6. An electronic device, characterized in that, The electronic device includes a processor and a memory, wherein the memory stores at least one instruction, at least one program, a code set, or an instruction set, and the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the method for generating a malicious scanning response strategy as described in any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, the at least one program, the code set, or instruction set is loaded and executed by a processor to implement the method for generating a malicious scanning response strategy as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Malicious traffic intrusion detection system and hardware platform

    CN113194091A

  • Network security protection method and device, computer equipment and storage medium

    CN116545678A