An IDC information security management method and a terminal device

By adding feature identifiers to data packets and using deep analysis models to judge abnormal characteristics, the problem of difficulty in identifying abnormal packets in traditional packet processing methods is solved, and higher detection accuracy and network stability are achieved.

CN118368133BActive Publication Date: 2025-06-03HEBEI YIGUANG CLOUD DATA CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410619110.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-18
Publication Date
2025-06-03
Estimated Expiration
2044-05-18

AI Technical Summary

Technical Problem

Traditional packet processing methods lack in-depth mining and accurate identification of packet characteristics, resulting in abnormal packets being easily missed or misjudged, thereby reducing the stability of the network system.

Method used

By obtaining packet information from the same network subject, adding feature identifiers to the packets, generating feature packets, and using the preset deep analysis model to determine whether there are abnormal features in the feature packets, if they exist, block the packet.

Benefits of technology

Through feature identification, most normal data packets are quickly filtered out, reducing the computational burden of the deep analysis model, improving the accuracy of the detection results, and ensuring the stability of the network system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118368133B_ABST
    Figure CN118368133B_ABST
Patent Text Reader

Abstract

An IDC information security management method and a terminal device, which relate to the field of network security. In this method, packet information from the same network entity is obtained, and a feature identifier is added to the data information packet according to the packet information to generate a feature packet; whether the feature packet has abnormal features is judged through a preset in-depth analysis model; if there are abnormal features, the feature packet is blocked. Implementing the technical solution provided by this application achieves the effect of improving the stability of the operating state of the network system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and particularly to a method for IDC information security management and a terminal device. Background Art

[0002] In the field of network security, with the rapid development of digitalization, networking, and intelligence, the surging data traffic has made network attack means increasingly complex and diverse. Traditional data packet processing methods often filter based on simple source addresses and destination addresses, lacking in-depth exploration and accurate identification of data packet features, making it easy for abnormal data packets to be missed or misjudged, ultimately resulting in a reduction in the service performance of the network system or even service interruption.

[0003] Therefore, how to improve the stability of the operation state of the network system has become an urgent problem to be solved. Summary of the Invention

[0004] This application provides a method for IDC information security management and a terminal device, which can improve the stability of the operation state of the network system.

[0005] In a first aspect, this application provides a method for IDC information security management, including: obtaining data packet information from the same network entity, and adding a feature identifier to the data information packet according to the data packet information to generate a feature data packet; determining whether the feature data packet has abnormal features through a preset in-depth analysis model; if there are abnormal features, blocking the feature data packet.

[0006] By adopting the above technical solution, adding a feature identifier to the data information packet according to the data packet information can enable the preset in-depth analysis model to quickly filter out most normal data packets through the feature identifier, focusing on the data packets that may contain abnormal behaviors, so as to reduce the computational burden of the in-depth analysis model, improve the accuracy of the detection results, and thus accurately block the data packets with abnormalities, ensuring the stability of the operation state of the network system.

[0007] Optionally, before determining whether the feature data packet has abnormal features through the preset in-depth analysis model, the method further includes: identifying the threat type corresponding to the feature data packet through a deep packet inspection method; matching a threat feature library according to the threat type to determine the abnormal type corresponding to the feature data packet, and the abnormal type includes SYN flood attack, DNS amplification attack; adding an abnormal label to the feature data packet according to the abnormal type, and the abnormal label is used to indicate that the in-depth analysis model selects a corresponding preset analysis method to identify abnormal features.

[0008] By adopting the above technical solution, according to the feature identifier, the data packets can be quickly classified into a specific category, which can reduce the amount of data required for subsequent analysis through the deep packet inspection method, thereby improving the identification efficiency.

[0009] Optionally, before adding an exception label to the feature data packet according to the exception type, the method further includes: obtaining preset regular data packet features, where the regular data packet features include a traffic rate range and a data packet length; setting an exception label according to the data packet features, and the exception label corresponds to at least one data packet feature.

[0010] By adopting the above technical solution, by presetting an exception label according to the data packet features in advance, data packets that do not conform to these regular features can be identified more accurately, so that these data packets are marked as exceptions, improving the accuracy of the detection result.

[0011] Optionally, when the exception feature includes an unknown exception feature, before blocking the feature data packet if there is an exception feature, the method further includes: determining whether the exception feature is an unknown exception feature; if it is an unknown exception feature, obtaining the source address information of the sent feature data packet; sending the feature data packet according to the communication permission corresponding to the source address information.

[0012] By adopting the above technical solution, by identifying and processing unknown exception features, the detection device can make a quick response when encountering new or unknown threats, thereby reducing the blocking of normal communication caused by misjudgment while enhancing the overall network security.

[0013] Optionally, after sending the feature data packet according to the communication permission corresponding to the source address information, the method further includes: obtaining the sending result corresponding to the sent feature data packet, and determining whether the sending result is a secure state; if it is a secure state, obtaining the unknown feature label of the unknown exception feature corresponding to the feature data packet, and setting the unknown feature label as a trustworthy feature.

[0014] By adopting the above technical solution, by verifying the security of unknown exception features and marking the exception features corresponding to data packets that do not cause attacks as trustworthy features, the accuracy and adaptability of the judgment result of the detection device can be improved.

[0015] Optionally, after blocking the feature data packet, the method further includes: if it is a non-secure state, obtaining the content features corresponding to the data packet information, where the content features include a traffic pattern, a data packet length, and a payload content feature; generating an interception label according to the content features and the exception features, and the interception label is used to block data packets whose similarity to the feature data packet is greater than a preset similarity.

[0016] By adopting the above technical solution, generating an interception label according to the content features, blocking data packets with exception features, and generating an interception label based on their content features can more comprehensively identify and block potential network threats, thereby improving the overall security of the network.

[0017] Optionally, before determining whether the feature data packet has abnormal features through the preset depth analysis model, the method further includes: obtaining event data, where the event data includes normal data packets and attack data packets; adding abnormal feature labels to the event data to generate a training data set; training the initial depth analysis model through the training data set to obtain the preset depth analysis model.

[0018] By adopting the above technical solution, through the training of a large amount of event data, the preset depth analysis model can more accurately identify abnormal behaviors in the network, and by adaptively coping with changes in the network environment and attack techniques, it can continuously update and learn new abnormal features, thereby reducing false alarms and missed detections of abnormal features.

[0019] In a second aspect of the present application, a terminal device is provided, including: an acquisition module, configured to acquire data packet information from the same network entity, and add a feature identifier to the data information packet according to the data packet information to generate a feature data packet; a judgment module, configured to determine whether the feature data packet has abnormal features through the preset depth analysis model; a blocking module, configured to block the feature data packet if there are abnormal features.

[0020] In a third aspect of the present application, an electronic device is provided, including a processor (401), a memory (405), a user interface (403), and a network interface (404). The memory (405) is used to store instructions, the user interface (403) and the network interface (404) are used to communicate with other devices, and the processor (401) is used to execute the instructions stored in the memory (405) so that the electronic device (400) executes the method according to any one of the first aspects.

[0021] In a fourth aspect of the present application, a computer-readable storage medium is provided. The computer-readable storage medium stores instructions, and when the instructions are executed, the method steps according to any one of the first aspects are executed.

[0022] In summary, one or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages:

[0023] 1. By adding a feature identifier to the data packet, most normal data packets can be quickly filtered out, which can improve the accuracy of the detection result, accurately block the data packets with abnormalities, and ensure the stability of the operation state of the network system.

[0024] 2. Based on the feature identifier to identify the abnormal features corresponding to the data packet, the amount of data required for subsequent analysis by the deep packet detection method can be reduced, and the recognition efficiency can be improved.

[0025] 3. By setting and verifying the security of unknown exception features and marking the exception features corresponding to the non - attacking data packets as trusted features, the accuracy and self - adaptability of the judgment results of the detection device can be improved. Brief Description of the Drawings

[0026] Figure 1 It is a schematic diagram of the IDC information security management scenario provided by the embodiment of the present application.

[0027] Figure 2 It is a flowchart of the IDC information security management method disclosed by the embodiment of the present application.

[0028] Figure 3 It is a schematic diagram of the structure of a terminal device disclosed by the embodiment of the present application.

[0029] Figure 4 It is a schematic diagram of the structure of an electronic device disclosed by the embodiment of the present application. Detailed Embodiments

[0030] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments.

[0031] In the description of the embodiments of the present application, words such as "for example" or "for illustration" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "for example" or "for illustration" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, the use of words such as "for example" or "for illustration" is intended to present relevant concepts in a specific way.

[0032] In the description of the embodiments of the present application, the meaning of the term "a plurality of" refers to two or more. For example, a plurality of systems refers to two or more systems, and a plurality of screen terminals refers to two or more screen terminals. In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the technical features indicated. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. The terms "include", "comprise", "have" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0033] The IDC information security management method provided by the embodiments of the present application can be applied to the scenario of IDC information security management. As Figure 1In the shown scenario, it includes a terminal device A101, a switch 102, a detection device 103, and a terminal device B104. Among them, the terminal device A101 and the terminal device 104B receive or send data packets through the switch 102. The switch 102 is used to copy the data packets and traffic data sent by the terminal device A101 and the terminal device 104B, and send the copied data packets and traffic data to the detection device 103, so that the detection device 103 can determine whether the data packets are abnormal, and instruct the switch 102 to block the data packets when it determines that the data packets are abnormal.

[0034] Optionally, the detection device 103 can be installed in the switch 102, and the present application does not make specific limitations on this.

[0035] Based on Figure 1 the shown application scenario, please continue to refer to Figure 2 , Figure 2 which is a process 200 of the IDC information security management method provided by the embodiments of the present application. The IDC information security management method is applied to Figure 1 the shown detection device 103.

[0036] Next, Figure 2 a detailed description of an IDC information security management method according to an embodiment of the present application will be given.

[0037] Step S201: Obtain data packet information from the same network entity, and add a feature identifier to the data information packet according to the data packet information to generate a feature data packet.

[0038] The same network entity can be any device or system that generates network traffic. For example, a server, a client computer, a mobile device, an Internet of Things device, etc.

[0039] The data packet information is used to represent the detailed content and attributes of the data packets received from the network. For example, the data packet information can include five-tuple information (source IP, destination IP, source port, destination port, and protocol type), data type, the length of the data packet, etc.

[0040] A feature identifier is a tag used to quickly identify and classify data packets with common attributes, which can be one or more tags or attributes. It is easy to understand that before adding a feature identifier to a data packet, a mapping relationship is set between the data packet information and the feature identifier. For example, according to the list of data that has launched a SYN flood attack as [192.168.0.1, 192.168.0.2, 192.168.0.3], then add [IP_192.168.0.2 _SYN] to the data packet sent by 192.168.0.2, and set the data packet quantity threshold to 20. When it exceeds 20, a feature identifier is generated. Optionally, for normal data packet information, the feature identifier format can be set as [SourceIP_DestIP_Protocol_Port], where SourceIP and DestIP are the source and destination IP addresses, Protocol is the protocol used (such as TCP, UDP), and Port is the port number of the data packet. For example, the feature identifier can be [192.168.1.100_203.0.113.25_TCP_80].

[0041] Exemplarily, since the captured data packets may come from different parts of the network (such as local area network, wide area network), the detection device uses a network monitoring tool or a security device (such as an intrusion detection system) to capture data packets from the network traffic, then identifies the network entity with the IP address of 192.168.1.100 through the data packet information, and then determines based on the data packet information that 192.168.1.100 sends a large number of TCP SYN data packets to port 80 (HTTP service). Thus, based on this information, the detection device generates the feature identifier [IP_192.168.1.100_TCP_SYN_TO_PORT_80].

[0042] Step S202: Determine whether the feature data packet has abnormal features through a preset depth analysis model.

[0043] In an alternative embodiment, before determining whether the feature data packet has abnormal features through a preset depth analysis model, the method further includes: obtaining event data, where the event data includes normal data packets and aggressive data packets; adding abnormal feature tags to the event data to generate a training data set; training an initial depth analysis model through the training data set to obtain the preset depth analysis model.

[0044] Exemplarily, a large number of network data packets are collected as event data, which include normal data packets and known aggressive data packets. Abnormal feature tags are added to the event data, that is, corresponding abnormal feature tags are added to the normal data packets and the aggressive data packets respectively. For example, for the aggressive data packets, tags such as "SYN flood attack", "DDoS attack", "XSS attack" can be added. Then, the labeled event data is divided into a training set and a validation set (optionally also including a test set), and the initial deep analysis model is trained through the training data set to obtain a preset deep analysis model.

[0045] In this embodiment, through the training of a large amount of event data, the preset deep analysis model can more accurately identify abnormal behaviors in the network. Moreover, by adaptively coping with changes in the network environment and attack methods, new abnormal features can be continuously updated and learned, thereby reducing false alarms and missed alarms of abnormal features.

[0046] In an alternative embodiment, before determining whether a feature data packet has an abnormal feature through the preset deep analysis model, the method further includes: identifying the threat type corresponding to the feature data packet through a deep packet inspection method; matching a threat feature library for the feature data packet according to the threat type to determine the abnormal type corresponding to the feature data packet, and the abnormal type includes SYN flood attack, DNS amplification attack; adding an abnormal label to the feature data packet according to the abnormal type, and the abnormal label is used to instruct the deep analysis model to identify the abnormal feature according to the selected preset analysis method.

[0047] The threat feature library is a database used to identify network threats in the deep packet inspection method. In the embodiments of the present application, the threat feature library contains feature information of various known network attack patterns and malicious behaviors, and can match the data packets with the feature information in the threat feature library to determine whether the data packets are threatened.

[0048] Combined with the above example, the feature identifier is [IP_192.168.1.100_TCP_SYN_TO_PORT_80]. The deep packet inspection (DPI) method can quickly identify the source IP address, protocol type (TCP), packet type (SYN), and destination port number corresponding to the data packet according to the feature identifier, and learn that these data packets may be subject to a SYN flood attack. Therefore, the deep packet inspection method can match the SYN flood attack feature library for the data packet according to the protocol type (TCP), packet type (SYN packet), and port number (80) corresponding to the data packet, and analyze the data packet to determine that the number of sent data packets is excessive, consider that there is a SYN flood attack, and add a SYN flood attack label to the data packet.

[0049] In this embodiment, data packets can be quickly classified into a specific category according to the feature identifier, which can reduce the amount of data required for subsequent analysis by the deep packet detection method, thereby improving the recognition efficiency.

[0050] In an alternative embodiment, before adding an exception label to the feature data packet according to the exception type, the method further includes: obtaining preset normal data packet features, where the normal data packet features include a traffic rate range and a data packet length; setting an exception label according to the data packet features, and the exception label corresponds to at least one data packet feature.

[0051] It is easy to understand that the normal data packet features are the features corresponding to the data packets without security threats. The normal data packets may further include more features (such as timestamps), which are not specifically limited in this application.

[0052] Exemplarily, according to the performance of the terminal device, the normal data packet features are set as [traffic rate range: 1 Mbps - 100 Mbps, data packet length: 576 bytes - 65535 bytes]. An exception label is set according to the data packet features. Among them, the exception label corresponding to the traffic rate range is [traffic amplification attack], and the exception labels corresponding to the data packet length are [Ping of Death attack, Teardrop attack].

[0053] In this embodiment, by presetting the exception label according to the data packet features, data packets that do not conform to these normal features can be more accurately identified, and these data packets can be marked as exceptions, improving the accuracy of the detection result.

[0054] Step S203: If there are abnormal features, block the feature data packet.

[0055] Exemplarily, if there are abnormal features, the detection device sends a blocking instruction to the switch to prevent the switch from sending the feature data packet to the application device B.

[0056] The IDC information security management method provided by the embodiments of this application can add a feature identifier according to the data packet information data packet, enabling the preset deep analysis model to quickly filter out most normal data packets through the feature identifier, focusing on the data packets that may contain abnormal behaviors, reducing the computational burden of the deep analysis model, improving the accuracy of the detection result, and thus accurately blocking the data packets with abnormalities to ensure the stability of the operation state of the network system.

[0057] In an alternative embodiment, when the abnormal feature includes an unknown abnormal feature and before blocking the feature data packet if there is an abnormal feature, the method further includes: determining whether the abnormal feature is an unknown abnormal feature; if it is an unknown abnormal feature, obtaining the source address information of the sent feature data packet; and sending the feature data packet according to the communication permission corresponding to the source address information.

[0058] The communication permission refers to the communication permission set according to different types of source address information before sending the feature data packet according to the communication permission corresponding to the source address information. For example, if the communication times corresponding to the source address are greater than 100, it is set in the white list, and if the source address that has sent aggressive data packets twice is set in the black list. The unknown abnormal feature refers to an abnormal feature that is not predefined.

[0059] Combined with the above example, if the corresponding abnormal label [traffic amplification attack] is not predefined according to the traffic rate range, when the traffic flow rate does not belong to 1 Mbps - 100 Mbps, for example, when it is 200 Mbps, the abnormal feature corresponding to the data packet is an unknown abnormal feature. When it is determined that the feature corresponding to the data packet is an unknown abnormal feature, the source address information of the data packet is obtained, such as IP_192.168.1.100. If 192.168.1.100 is in the preset white list, the detection device instructs the switch to send the data packet to the application device B according to the normal steps. If it is in the access control list, the switch is instructed to send the data packet to the application device B within a preset time period. If it is in the black list, the data packet is blocked.

[0060] It should be understood that the communication permission is also adjusted according to actual application requirements, and the present application does not make specific limitations on this.

[0061] In this embodiment, by identifying and processing unknown abnormal features, the detection device can make a quick response when encountering new or unknown threats, thereby reducing the blocking of normal communication caused by misjudgment while enhancing the overall network security.

[0062] In an alternative embodiment, after sending the feature data packet according to the communication permission corresponding to the source address information, the method further includes: obtaining the sending result corresponding to the sent feature data packet, and determining whether the sending result is in a safe state; if it is in a safe state, obtaining the unknown feature label of the unknown abnormal feature corresponding to the feature data packet and setting the unknown feature label as a trustworthy feature.

[0063] The sending result is used to represent the state of the device that receives the data packet. Combining the above example, and taking the source address corresponding to the data packet as 192.168.1.100 and the length as 60000 bytes as an example, after sending the characteristic data packet, the detection device checks whether the captured data packet triggers an alarm. If not, it means that the application device B is in a safe state. The unknown abnormal characteristic corresponding to the data packet is obtained as [flow rate: high speed 200Mbps], the unknown characteristic label is set as [high speed_medium length_local address], and [high speed_medium length_local address] is set as a trustworthy characteristic. It should be understood that when the abnormal characteristic corresponding to the data packet is a trustworthy characteristic, the data packet is not blocked. It should also be understood that in this example, the flow rate is high speed within 100Mbps - 200Mbps, and the data packet length is medium length within 60000 bytes - 65535 bytes.

[0064] In this embodiment, by verifying the security of the unknown abnormal characteristic and marking the abnormal characteristic corresponding to the data packet that does not cause an attack as a trustworthy characteristic, the accuracy and self - adaptability of the judgment result of the detection device can be improved.

[0065] In an alternative embodiment, after blocking the characteristic data packet, the method further includes: if it is in a non - safe state, obtaining the content characteristics corresponding to the data packet information, where the content characteristics include traffic pattern, data packet length, and payload content characteristics; generating an interception label according to the content characteristics and the unknown abnormal characteristic, and the interception label is used to block data packets whose similarity to the characteristic data packet is greater than a preset similarity.

[0066] Combining the above example, and taking the preset similarity as 60% as an example, if the alarm of the application device B is triggered, it means that the application device B is in a non - safe state, where the flow rate corresponding to the data packet is 180Mbps, the data packet length is 65000 bytes, the payload content is text, and the source address is 85.214.234.123 (non - local address). Then the content characteristics are set as [high speed_medium length_text_non - local address], the unknown abnormal characteristic is [flow rate: high speed 200Mbps], and the interception label [high speed_medium length_text_non - local address] is generated. If a data packet with an abnormal characteristic of [high speed_medium length_text_local address] is detected, it is blocked.

[0067] It should be understood that the content characteristics may also include more content (such as the above - mentioned source address), and the present application does not make specific limitations on this.

[0068] In this embodiment, generating an interception label according to the content characteristics, blocking data packets with abnormal characteristics, and generating an interception label based on their content characteristics can more comprehensively identify and block potential network threats, thereby improving the overall security of the network.

[0069] It can be understood that in order for the detection device to achieveFigure 2 The functions described above include the corresponding hardware and / or software modules for performing each function. In combination with the steps of the examples described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving the hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application in combination with the embodiments, but such implementation should not be considered to exceed the scope of the present application.

[0070] In this embodiment, the terminal device can be divided into functional modules according to the above method examples. For example, each different functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is illustrative, only a logical function division, and there may be other division methods in actual implementation.

[0071] In the case of dividing each functional module corresponding to each function, Figure 3 FIG. shows a possible schematic diagram of the terminal device 300 involved in the above embodiment. The terminal device 300 includes: an acquisition module 301, configured to acquire packet information from the same network entity, and add a feature identifier to the data information packet according to the packet information to generate a feature packet; a judgment module 302, configured to judge whether the feature packet has an abnormal feature through a preset depth analysis model; a blocking module 303, configured to block the feature packet if there is an abnormal feature.

[0072] In an optional implementation manner of the embodiment of the present application, the judgment module 302 is further configured to identify the threat type corresponding to the feature packet through a deep packet detection method; match the threat feature library according to the threat type to judge the abnormal type corresponding to the feature packet, and the abnormal type includes SYN flood attack, DNS amplification attack; add an abnormal label to the feature packet according to the abnormal type, and the abnormal label is used to instruct the depth analysis model to identify the abnormal feature according to the selected corresponding preset analysis method.

[0073] In an optional implementation manner of the embodiment of the present application, the judgment module 302 is further configured to acquire preset conventional packet features, and the conventional packet features include a traffic rate range and a packet length; set an abnormal label according to the packet features, and the abnormal label corresponds to at least one packet feature.

[0074] In an alternative implementation of the embodiment of the present application, the blocking module 303 is further configured to determine whether the abnormal feature is an unknown abnormal feature; if it is an unknown abnormal feature, obtain the source address information of the sent feature data packet; and send the feature data packet according to the communication permission corresponding to the source address information.

[0075] In an alternative implementation of the embodiment of the present application, the blocking module 303 is further configured to obtain the sending result corresponding to the sent feature data packet, and determine whether the sending result is a secure state; if it is a secure state, obtain the unknown feature label of the unknown abnormal feature corresponding to the feature data packet, and set the unknown feature label as a trustworthy feature.

[0076] In an alternative implementation of the embodiment of the present application, the blocking module 303 is further configured to, if it is a non-secure state, obtain the content features corresponding to the data packet information, where the content features include a traffic pattern, a data packet length, and a payload content feature; generate an interception label according to the content features and the abnormal features, and the interception label is used to block data packets whose similarity to the feature data packet is greater than a preset similarity.

[0077] In an alternative implementation of the embodiment of the present application, before the determination module 302 determines whether the feature data packet has an abnormal feature through a preset depth analysis model, the method further includes: obtaining event data, where the event data includes normal data packets and aggressive data packets; adding an abnormal feature label to the event data to generate a training data set; and training an initial depth analysis model through the training data set to obtain a preset depth analysis model.

[0078] The present application also discloses an electronic device. Refer to Figure 4 , Figure 4 FIG. is a schematic structural diagram of an electronic device disclosed in the embodiment of the present application. The electronic device 400 may include: at least one processor 401, at least one network interface 404, a user interface 403, a memory 405, and at least one communication bus 402.

[0079] Among them, the communication bus 402 is used to realize the connection and communication between these components.

[0080] Among them, the user interface 403 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 403 may further include a standard wired interface and a wireless interface.

[0081] Among them, the network interface 404 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).

[0082] Among them, the processor 401 may include one or more processing cores. The processor 401 connects various parts within the entire server through various interfaces and lines. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 405, and by calling the data stored in the memory 405, it performs various functions of the server and processes data. Optionally, the processor 401 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 401 may integrate a combination of one or several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 401 and may be implemented separately by a single chip.

[0083] Among them, the memory 405 may include random access memory (RAM) and may also include read-only memory. Optionally, the memory 405 includes a non-transitory computer-readable storage medium. The memory 405 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 405 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store the data involved in the above-mentioned various method embodiments. Optionally, the memory 405 may also be at least one storage device located far from the aforementioned processor 401. Refer to Figure 4 , in the memory 405 as a computer storage medium, there may be included an operating system, a network communication module, a user interface module, and an application program of an IDC information security management method.

[0084] In Figure 4In the electronic device 400 shown, the user interface 403 is mainly used to provide an interface for the user to input and obtain the data input by the user; and the processor 401 can be used to call an application program storing an IDC information security management method in the memory 405. When executed by one or more processors 401, the electronic device 400 is caused to execute one or more of the methods as described in the above embodiments. It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, some steps can be adopted in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0085] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0086] In several implementation manners provided by this application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some service interfaces. The indirect couplings or communication connections of the devices or units can be in electrical or other forms.

[0087] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0088] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit exists physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0089] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present application. The aforementioned memory includes various media that can store program codes, such as USB flash drives, mobile hard disks, magnetic disks, or optical discs.

[0090] The foregoing are only exemplary embodiments of the present disclosure and should not be used to limit the scope of the present disclosure. That is, any equivalent changes and modifications made in accordance with the teachings of the present disclosure still fall within the scope covered by the present disclosure.

[0091] The present application aims to cover any variations, uses, or adaptive changes of the present disclosure. These variations, uses, or adaptive changes follow the general principles of the present disclosure and include well-known common knowledge or conventional technical means in the technical field not recorded in the present application. The description and the embodiments are only regarded as exemplary, and the scope and spirit of the present disclosure are defined by the claims.

Claims

1. An IDC information security management method, applied to a detection device, characterized in that: include: Acquire data packet information from the same network subject, and add a characteristic identifier to the data packet according to the data packet information to generate a characteristic data packet; Determine whether the characteristic data packet has abnormal characteristics through a preset deep analysis model; If the abnormal feature exists, blocking the feature data packet; Before determining whether the characteristic data packet has abnormal characteristics through a preset deep analysis model, the method further includes: Identify the threat type corresponding to the characteristic data packet by a deep packet inspection method; Matching the characteristic data packet with a threat feature library according to the threat type to determine an abnormality type corresponding to the characteristic data packet, wherein the abnormality type includes a SYN flood attack and a DNS amplification attack; Adding an abnormal label to the feature data packet according to the abnormal type, wherein the abnormal label is used to instruct the deep analysis model to identify the abnormal feature according to the corresponding preset analysis method; The abnormal feature includes an unknown abnormal feature. Before blocking the characteristic data packet if the abnormal feature exists, the method further includes: Determining whether the abnormal feature is the unknown abnormal feature; If it is the unknown abnormal feature, obtaining the source address information of the sent feature data packet; Sending the characteristic data packet according to the communication authority corresponding to the source address information; wherein the communication authority is set according to different types of source address information; Obtaining a sending result corresponding to sending the characteristic data packet, and determining whether the sending result is a safe state; wherein the sending result is used to indicate the state of the device receiving the characteristic data packet, and after sending the characteristic data packet, detecting whether the device captures the characteristic data packet and triggers an alarm, and if not, indicating that the device is in a safe state; If it is a safe state, obtaining the unknown feature label of the unknown abnormal feature corresponding to the feature data packet, and setting the unknown feature label as a trusted feature; After blocking the characteristic data packet, the method further includes: If it is a non-safe state, obtaining content characteristics corresponding to the characteristic data packet, wherein the content characteristics include flow mode, data packet length, and load content characteristics; An interception tag is generated according to the content feature and the unknown abnormal feature, and the interception tag is used to intercept data packets whose similarity with the characteristic data packet is greater than a preset similarity.

2. The method according to claim 1, characterized in that Before adding an exception label to the characteristic data packet according to the exception type, the method further includes: Acquire preset regular data packet characteristics, wherein the regular data packet characteristics include a flow rate range and a data packet length; The abnormal label is set according to the data packet feature, and the abnormal label corresponds to at least one data packet feature.

3. The method according to claim 1, characterized in that Before determining whether the characteristic data packet has abnormal characteristics by using a preset deep analysis model, the method further includes: Acquiring event data, wherein the event data includes normal data packets and offensive data packets; Adding abnormal feature labels to the event data to generate a training data set; The initial depth analysis model is trained using the training data set to obtain the preset depth analysis model.

4. A terminal device, characterized in that: Used to execute an IDC information security management method according to any one of claims 1 to 3, the terminal device comprises: An acquisition module, used to acquire data packet information from the same network subject, and add a characteristic identifier to the data packet according to the data packet information to generate a characteristic data packet; A judgment module, used to judge whether the characteristic data packet has abnormal characteristics through a preset deep analysis model; The blocking module is used to block the characteristic data packet if the abnormal characteristic exists.

5. An electronic device, characterized in that: The electronic device (400) comprises a processor (401), a memory (405), a user interface (403) and a network interface (404), wherein the memory (405) is used to store instructions, the user interface (403) and the network interface (404) are used to communicate with other devices, and the processor (401) is used to execute the instructions stored in the memory (405) so that the electronic device (400) executes the method according to any one of claims 1 to 3.

6. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed by a processor, the method steps according to any one of claims 1 to 3 are performed.

Citation Information

Patent Citations

  • Anti-intrusion detection system based on Snort engine and adopting logistic regression algorithm

    CN114124446A

  • Edge node network flow data processing method, device, equipment and medium

    CN117478434A