Information reverse tracing method, device and equipment and storage medium
By using reverse tracing methods and techniques such as sparse matrices and iterative training, the IP address of the attacker can be determined from the tracing database. This solves the problems of non-real-time and low efficiency in reverse tracing in existing technologies, and improves network security and tracing accuracy.
Patent Information
- Application Number
- CN202410465573.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-17
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2044-04-17
AI Technical Summary
In existing technologies, the methods for reverse tracing to determine the attacker's relevant information rely on manual operation, resulting in non-real-time, low accuracy, poor completeness, low analysis efficiency, and poor network security.
The method of reverse tracing is adopted. By obtaining the reverse tracing requirement information and inputting it into the reverse tracing model, the IP address of the attacker is determined from the tracing database using sparse matrix, iterative training and byte comparison algorithms. This includes data analysis and processing such as data collection, data filtering, data cleaning and attack behavior detection.
It enables efficient analysis of information related to attack behavior, improves network security, reduces the need for manual verification, and enhances the accuracy and completeness of the tracing results.
Smart Images

Figure CN118400139B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computers, and in particular to an information reverse tracing method and device, equipment and a storage medium. BACKGROUND
[0002] When a terminal / network is subjected to an attack threat behavior, the attack party can be traced in reverse based on the attack threat behavior to determine relevant information (such as an IP address, identity information, location information, etc.) of the attack party and take corresponding protection measures.
[0003] However, the current way of determining the relevant information of the attack party through reverse tracing mainly relies on manual operation and the like, and the relevant information of the attack party can be checked through manual operation only after being subjected to the attack threat behavior. The tracing result obtained in this case is non-real-time processing, has low accuracy and poor completeness, and the efficiency of analyzing the relevant information of the attack threat behavior is low and the network security is poor. SUMMARY
[0004] The present application provides an information reverse tracing method, device, equipment and a storage medium, which are used to improve the efficiency of analyzing the relevant information of the attack behavior and improve network security.
[0005] To achieve the above object, the present application adopts the following technical solutions:
[0006] In a first aspect, an information reverse tracing method is provided, which includes: obtaining reverse tracing requirement information, the reverse tracing requirement information being attack information determined when a network is subjected to an attack behavior, the reverse tracing requirement information including at least one of the following: a data flow direction, a source IP address, a destination IP address, a data propagation state, a next-hop IP address, and an attack time; inputting the reverse tracing requirement information into a reverse tracing model to determine an IP address of an attack party corresponding to the reverse tracing requirement information from a tracing database, the reverse tracing model being used for data analysis and processing of the reverse tracing requirement information, the data analysis and processing including at least one of the following: data collection, data filtering, data cleaning, attack behavior detection, and IP address tracing, and the tracing database including a plurality of byte streams, each byte stream including a plurality of byte data.
[0007] In a possible implementation, inputting the reverse tracing requirement information into the reverse tracing model to determine the IP address of the attack party corresponding to the reverse tracing requirement information from the tracing database includes: constructing a sparse matrix based on the reverse tracing requirement information, the sparse matrix being used to represent the reverse tracing requirement information; inputting the sparse matrix into the reverse tracing model to determine the IP address of the attack party corresponding to the reverse tracing requirement information from the tracing database.
[0008] In a possible implementation, the reverse tracing demand information is input into the reverse tracing model, and an IP address of an attacker corresponding to the reverse tracing demand information is determined from the tracing database, including: inputting the reverse tracing demand information and initial training parameters into the reverse tracing model, performing multiple iteration training on the reverse tracing model, and the output result of each iteration training includes an IP address determined from the tracing database and training parameters after iteration training, and the initial training parameters include: initial tracing accuracy, initial tracing path integrity rate, and initial tracing analysis efficiency; in the case that the iteration training is performed for a preset number of times, and the training parameters after each iteration training all meet the preset condition, the IP address determined from the tracing database in the last iteration training is taken as the IP address of the attacker corresponding to the reverse tracing demand information.
[0009] In a possible implementation, the reverse tracing demand information and the initial training parameters are input into the reverse tracing model, and the reverse tracing model is trained for multiple iterations, including: analyzing the reverse tracing demand information to obtain multiple address strings, each address string in the multiple address strings including multiple bytes; comparing the multiple address strings with multiple byte streams included in the tracing database respectively, determining the IP address corresponding to the reverse tracing demand information from the tracing database, and determining the training parameters after iteration training based on the initial training parameters.
[0010] In a possible implementation, the multiple address strings are compared with the multiple byte streams included in the tracing database respectively, and the IP address corresponding to the reverse tracing demand information is determined from the tracing database, including: for any address string and any byte stream, determining a comparison parameter of the any address string and the any byte stream based on a byte comparison algorithm; determining the IP address corresponding to the reverse tracing demand information from the tracing database based on the comparison parameter of each address string and each byte stream.
[0011] In a possible implementation, the initial training parameters include: training parameters input in the current iteration training and historical maximum training parameters; and the training parameters after iteration training are determined based on the initial training parameters, including: in the process of each iteration training, the training parameters after the current iteration training are determined based on the training parameters input in the current iteration training and the historical maximum training parameters by using a semi-supervised learning algorithm.
[0012] In a possible implementation, in a case where the preset number of iteration training is passed and the training parameters after each iteration training all satisfy the preset condition, the IP address determined from the traceability database in the last iteration training is taken as the IP address of the attacker corresponding to the reverse traceability requirement information, including: starting the next iteration training in a case where the training parameters after each iteration training are determined to satisfy the preset condition by a training parameter evaluation algorithm, the training parameter evaluation algorithm being used to determine whether the training parameters satisfy the training condition; performing the next iteration training on the reverse traceability model based on the training parameters after the last iteration training, and taking the IP address determined from the traceability database in the last iteration training as the IP address of the attacker corresponding to the reverse traceability requirement information in a case where the number of iteration training reaches the preset number.
[0013] In a second aspect, an information reverse traceability apparatus is provided, including: an acquisition unit and a processing unit.
[0014] The acquisition unit is configured to acquire reverse traceability requirement information, the reverse traceability requirement information being attack information determined when a network is attacked, and the reverse traceability requirement information including at least one of the following: data flow direction, source IP address, destination IP address, data propagation state, next-hop IP address, and attack time. The processing unit is configured to input the reverse traceability requirement information into a reverse traceability model, and determine an IP address of an attacker corresponding to the reverse traceability requirement information from a traceability database, the reverse traceability model being used to perform data analysis and processing on the reverse traceability requirement information, and the data analysis and processing including at least one of the following: data collection, data filtering, data cleaning, attack behavior detection, and IP address traceability. The traceability database includes a plurality of byte streams, and each byte stream includes a plurality of byte data.
[0015] In a possible implementation, the processing unit is specifically configured to construct a sparse matrix based on the reverse traceability requirement information, the sparse matrix being used to represent the reverse traceability requirement information. The processing unit is specifically configured to input the sparse matrix into the reverse traceability model, and determine the IP address of the attacker corresponding to the reverse traceability requirement information from the traceability database.
[0016] In a possible implementation, the processing unit is specifically configured to input the reverse tracing demand information and initial training parameters into the reverse tracing model, perform multiple iteration training on the reverse tracing model, and the output result of each iteration training includes an IP address determined from the tracing database and a training parameter after iteration training, and the initial training parameters include an initial tracing accuracy, an initial tracing path integrity rate, and an initial tracing analysis efficiency; the processing unit is specifically configured to, in a case where the iteration training reaches a preset number of times and the training parameter after each iteration training meets a preset condition, determine the IP address from the tracing database in the last iteration training as the IP address of the attacker corresponding to the reverse tracing demand information.
[0017] In a possible implementation, the processing unit is specifically configured to parse the reverse tracing demand information to obtain a plurality of address strings, and each address string in the plurality of address strings includes a plurality of bytes; the processing unit is specifically configured to compare the plurality of address strings with a plurality of byte streams included in the tracing database respectively, determine the IP address corresponding to the reverse tracing demand information from the tracing database, and determine the training parameter after iteration training based on the initial training parameter.
[0018] In a possible implementation, the processing unit is specifically configured to, for any one address string and any one byte stream, determine a comparison parameter of any one address string and any one byte stream based on a byte comparison algorithm; and the processing unit is specifically configured to determine the IP address corresponding to the reverse tracing demand information from the tracing database based on the comparison parameter of each address string and each byte stream.
[0019] In a possible implementation, the initial training parameters include a training parameter input in a current iteration training and a historical maximum training parameter; and the processing unit is specifically configured to, in a process of each iteration training, determine the training parameter after the current iteration training based on the training parameter input in the current iteration training and the historical maximum training parameter by using a semi-supervised learning algorithm.
[0020] In a possible implementation, the processing unit is specifically configured to, after each iteration training, start the next iteration training in a case where the training parameter evaluation algorithm is used to determine that the training parameter after iteration training meets the preset condition, and the training parameter evaluation algorithm is used to determine whether the training parameter meets a training condition; the processing unit is specifically configured to perform the next iteration training on the reverse tracing model based on the training parameter after the last iteration training, and in a case where the number of iteration training reaches a preset number of times, determine the IP address from the tracing database in the last iteration training as the IP address of the attacker corresponding to the reverse tracing demand information.
[0021] In a third aspect, an electronic device includes a processor and a memory. The memory is configured to store one or more programs including computer-executable instructions. When the electronic device is running, the processor executes the computer-executable instructions stored in the memory, so that the electronic device performs the information reverse tracing method according to the first aspect.
[0022] In a fourth aspect, a computer-readable storage medium storing one or more programs is provided. The one or more programs include instructions that, when executed by a computer, cause the computer to perform the information reverse tracing method according to the first aspect.
[0023] The present application provides an information reverse tracing method, device, equipment and storage medium, which is applied to the scene of reverse tracing attack information when a network is attacked. When the network is attacked, reverse tracing demand information including at least one of data flow direction, source IP address, destination IP address, data propagation state, next hop IP address and attack time is obtained, and the reverse tracing demand information is input into a reverse tracing model for data analysis and processing, so as to determine the IP address of the attacker corresponding to the reverse tracing demand information from a tracing database. Based on the above scheme, the attack information obtained can be analyzed and processed by the reverse tracing model, so as to determine the IP address of the corresponding attacker based on the plurality of byte streams included in the tracing database. Without manual checking of the attack behavior, the efficiency of analyzing the information related to the attack behavior can be improved, and the network security can be improved. BRIEF DESCRIPTION OF DRAWINGS
[0024] Figure 1 A schematic diagram of an information reverse tracing system structure is provided for an embodiment of the present application.
[0025] Figure 2 A schematic diagram of an information reverse tracing method flow is provided for an embodiment of the present application. Figure 1 ;
[0026] Figure 3 A schematic diagram of an information reverse tracing method flow is provided for an embodiment of the present application. Figure 2 ;
[0027] Figure 4 A schematic diagram of an information reverse tracing method flow is provided for an embodiment of the present application. Figure 3 ;
[0028] Figure 5 A schematic diagram of an information reverse tracing method flow is provided for an embodiment of the present application. Figure 4 ;
[0029] Figure 6An information reverse tracing method flowchart provided for an embodiment of the present application Figure 5 ;
[0030] Figure 7 An information reverse tracing method flowchart provided for an embodiment of the present application Figure 6 ;
[0031] Figure 8 An information reverse tracing method flowchart provided for an embodiment of the present application Figure 7 ;
[0032] Figure 9 A data storage model schematic diagram provided for an embodiment of the present application
[0033] Figure 10 An information reverse tracing device structure schematic diagram provided for an embodiment of the present application
[0034] Figure 11 An electronic device structure schematic diagram provided for an embodiment of the present application DETAILED DESCRIPTION
[0035] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application.
[0036] In the description of the present application, unless otherwise specified, " / " means "or", for example, A / B can mean A or B. "And / or" in this document is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can mean that A exists alone, A and B exist together, and B exists alone. In addition, "at least one" "multiple" means two or more. "First", "second", etc. do not limit the quantity and execution order, and "first", "second", etc. also do not necessarily mean different.
[0037] Currently, Artificial Intelligence (AI) is a technology science that studies and develops theories, methods, technologies and application systems for simulation, extension and expansion, which is a branch of computer science. The research in the field of AI includes robots, voice recognition, image recognition, natural language processing and expert systems, etc. AI has more obvious advantages and more powerful functions in practical application. It is of great significance to develop the network monitoring function (Net Flow) traffic AI analysis multi-layer onion reverse tracing method rapidly and continuously.
[0038] With the upgrading of the system and the patching of the vulnerability, the virus attack mode of invading the host and then destroying gradually reduces the proportion in the attack, and these attacks change to maliciously consume the limited resources of the network or occupy the system, and then destroy the ability of the system to provide external services; but the traditional system upgrade cannot detect and prevent such attacks. For such attacks, the industry has proposed a method of detecting network data flow to judge network anomalies and attacks: with the help of real-time detection of network data flow information, by matching with historical records (judging whether it is normal) or matching with abnormal patterns (judging whether it is attacked), network managers can view the status of the entire network in real time, detect possible bottlenecks in network performance, and automatically process or alarm to ensure efficient and reliable network operation.
[0039] Net Flow is a network monitoring function that can collect the number and information of IP packets entering and leaving the network interface, and is applied to products such as routers and switches. By analyzing the information collected by Net Flow, network managers can know the source and destination of the packet, the type of network service, and the cause of network congestion.
[0040] The information reverse tracing method provided by the embodiment of the application can be applied to the information reverse tracing system. Figure 1 A structural schematic diagram of the information reverse tracing system is shown. As shown in Figure 1 The information reverse tracing system 20 includes a terminal device 21, a reverse tracing model 22, a network 23, and a user 24.
[0041] The terminal device 21 includes a preset network (for example, an enterprise intranet), the reverse tracing model 22 is used for data collection, data filtering, data cleaning, attack behavior detection, and IP address tracing processing of reverse tracing demand information, the network 23 can include a router, a firewall, and a core network, and the user 24 can be a personal user or an enterprise user.
[0042] The user 24 inputs the reverse tracing demand information into the terminal device 21, and then the terminal device 21 inputs the reverse tracing demand information into the reverse tracing model 22 to determine the IP address of the attack party corresponding to the reverse tracing demand information from a tracing database.
[0043] Next, a method for information reverse tracing provided by the embodiment of the application will be described with reference to the accompanying drawings. As shown in Figure 2 The method for information reverse tracing provided by the embodiment of the application includes S201-S202.
[0044] S201, obtain reverse tracing demand information.
[0045] The reverse tracing demand information is attack information determined when the network is attacked, and includes at least one of data flow direction, source IP address, destination IP address, data propagation state, next hop IP address, and attack time.
[0046] Optionally, when the network is attacked, the enterprise user or the individual user can determine attack information and send the attack information as the reverse tracing demand information to the enterprise intranet to determine the IP address of the attacker through the enterprise intranet and the reverse tracing model.
[0047] Specifically, the enterprise intranet can access the reverse tracing model through an internal network or a proxy to perform data analysis and processing on the reverse tracing demand information through the reverse tracing model. For example, the reverse tracing model can be an information tracing system based on AI autonomous learning.
[0048] S202, input the reverse tracing demand information into the reverse tracing model, and determine the IP address of the attacker corresponding to the reverse tracing demand information from the tracing database.
[0049] The reverse tracing model is used for data analysis and processing on the reverse tracing demand information, and the data analysis and processing includes at least one of data collection, data filtering, data cleaning, attack behavior detection, and IP address tracing. The tracing database includes a plurality of byte streams, and each byte stream includes a plurality of byte data.
[0050] Further, the reverse tracing model returns the tracing result (i.e., the IP address of the attacker) to the enterprise intranet, and returns the tracing result to the enterprise user or the individual user through the enterprise intranet.
[0051] It can be understood that inputting the reverse tracing demand information into the reverse tracing model can determine the IP address of the attacker corresponding to the reverse tracing demand information from the tracing database based on a preset algorithm (such as a semi-supervised learning algorithm or a training parameter evaluation algorithm).
[0052] It should be noted that the specific implementation of determining the IP address of the attacker corresponding to the reverse tracing demand information from the tracing database based on the reverse tracing model can refer to the following embodiments, which will not be described here.
[0053] The application provides an information reverse tracing method. When a network is attacked, at least one of reverse tracing demand information including data flow direction, source IP address, destination IP address, data propagation state, next hop IP address and attack time is obtained, and the reverse tracing demand information is input into a reverse tracing model for data analysis and processing, so as to determine the IP address of an attack party corresponding to the reverse tracing demand information from a tracing database. Based on the above scheme, the attack information obtained can be analyzed and processed by the reverse tracing model, so as to determine the IP address of the corresponding attack party based on multiple byte streams included in the tracing database. Without manual checking of the attack behavior, the efficiency of analyzing the information related to the attack behavior can be improved, and the network security is improved.
[0054] In one design, as shown in FIG. 1, the information reverse tracing method provided by the embodiments of the application includes the following steps. Figure 3 S202 can include S301-S302.
[0055] S301, constructing a sparse matrix based on the reverse tracing demand information.
[0056] The sparse matrix is used to represent the reverse tracing demand information.
[0057] Optionally, the reverse tracing demand information can be first data-converted to represent the reverse tracing demand information in the form of a sparse matrix.
[0058] For example, the sparse matrix can be represented by Formula 1.
[0059]
[0060] In this way, at least one of the data flow direction, source IP address, destination IP address, data propagation state, next hop IP address and attack time can be represented in the form of a sparse matrix.
[0061] It can be understood that the reverse tracing demand information obtained is not data information that can be recognized by the reverse tracing model, and therefore the reverse tracing demand information can be data-converted to construct a corresponding sparse matrix.
[0062] S302, inputting the sparse matrix into the reverse tracing model to determine the IP address of the attack party corresponding to the reverse tracing demand information from the tracing database.
[0063] In this way, based on the data information (i.e., the sparse matrix) that can be recognized by the reverse tracing model, the reverse tracing model can determine the IP address of the attack party corresponding to the reverse tracing demand information from the tracing database.
[0064] In the embodiments of the present application, by constructing a sparse matrix corresponding to the reverse tracing demand information, the accuracy of determining the IP address of the attacker corresponding to the reverse tracing demand information from the tracing database can be improved.
[0065] In one design, as shown in Figure 4 The information reverse tracing method provided by the embodiments of the present application can specifically include S401-S402 at S202.
[0066] S401, input the reverse tracing demand information and the initial training parameter into the reverse tracing model, and perform multiple iteration training on the reverse tracing model.
[0067] The output result of each iteration training includes the IP address determined from the tracing database and the training parameter after iteration training, and the initial training parameter includes the initial tracing accuracy, the initial tracing path integrity rate and the initial tracing analysis efficiency.
[0068] Optionally, when performing iteration training for the first time, the initial training parameter (i.e., the initial tracing accuracy The initial tracing path integrity rate The initial tracing analysis efficiency ) can be determined first. The initial training parameter can be a randomly determined parameter or a parameter determined according to historical data, which is not limited here.
[0069] It can be understood that when performing iteration training for the first time, the reverse tracing demand information and the initial training parameter need to be input into the reverse tracing model for the first iteration training.
[0070] Optionally, the number of iteration training can be a pre-set parameter, for example, the maximum number of iteration can be pre-set to 50 times, or 60 times, etc. The specific number of iteration is not limited here and is determined according to the specific scene.
[0071] S402, in the case that the iteration training is performed for the preset number of times and the training parameter after each iteration training meets the preset condition, the IP address determined from the tracing database by the last iteration training is taken as the IP address of the attacker corresponding to the reverse tracing demand information.
[0072] Optionally, when the training parameter after iteration training does not meet the preset condition, the iteration training is stopped and it is determined that the IP address of the attacker corresponding to the reverse tracing demand information cannot be determined from the tracing database.
[0073] In the embodiments of the present application, whether the reverse tracing model can determine the IP address of the attacker corresponding to the reverse tracing demand information from the tracing database can be determined by the training parameter, so that the iteration training can be terminated in time when the training parameter does not meet the preset condition.
[0074] In one design, as shown in Figure 5 In one design, as shown in
[0075] S501, parse the reverse tracing requirement information to obtain a plurality of address strings.
[0076] Each of the plurality of address strings includes a plurality of bytes.
[0077] Optionally, taking the IP address to be parsed (e.g., source IP address) as an example, the IP address to be parsed is parsed to obtain a plurality of address strings R[M][N], M is the Mth address string, and N is the Nth byte in the Mth address string.
[0078] Optionally, the plurality of byte streams included in the tracing database can be represented as S[U][V], U is the Uth byte stream, and V is the Vth byte data in the Uth byte stream.
[0079] S502, compare the plurality of address strings with the plurality of byte streams included in the tracing database, and determine the IP address corresponding to the reverse tracing requirement information from the tracing database.
[0080] Optionally, the matching rule corresponding to the tracing database can also be obtained to compare the plurality of address strings with the plurality of byte streams included in the tracing database based on the matching rule corresponding to the tracing database.
[0081] Specifically, when there are a plurality of reverse tracing requirement information, for each of the plurality of reverse tracing requirement information, the data flow direction, source IP address, destination IP address, data propagation state, next hop IP address, and attack time included in the reverse tracing requirement information can be parsed and compared with the plurality of byte streams included in the tracing database. If a matching byte stream is matched, the next byte stream is matched until the reverse tracing requirement information is matched and the corresponding IP address is determined. If no matching byte stream is matched, it is determined that no IP address is matched, and the matching fails.
[0082] S503, determine the training parameter after iterative training based on the initial training parameter.
[0083] It should be noted that the parameter input for the next iteration training of the reverse tracing model is the training parameter determined after the last iteration training, and then based on the input training parameter determined after the last iteration training and the reverse tracing requirement information input for the first iteration training, the IP address determined by the current iteration training and the training parameter can be output.
[0084] In the embodiments of the present application, the reverse tracing demand information can be analyzed to obtain a plurality of address strings, so as to compare the plurality of address strings with a plurality of byte streams included in the tracing database respectively, and determine the IP address corresponding to the reverse tracing demand information from the tracing database, thereby improving the accuracy of determining the IP address corresponding to the reverse tracing demand information.
[0085] In one design, as shown in FIG. 6, in the information reverse tracing method provided by the embodiments of the present application, S502 can specifically include S601-S602. Figure 6
[0086] S601, for any address string and any byte stream, determining the comparison parameter of any address string and any byte stream based on a byte comparison algorithm.
[0087] For example, the byte comparison algorithm is shown in Equation 2:
[0088]
[0089] Further, after determining the comparison parameter of any address string and any byte stream , it can be judged whether the comparison parameter satisfies a preset condition γ, so as to determine whether a matching byte stream can be matched.
[0090]
[0091] S602, determining the IP address corresponding to the reverse tracing demand information from the tracing database based on the comparison parameter of each address string and each byte stream.
[0092] It can be understood that based on the comparison parameter of any address string and any byte stream, the similarity between any address string and any byte stream can be determined, so as to determine the IP address corresponding to the reverse tracing demand information from the tracing database according to the comparison parameter between each address string and byte stream.
[0093] In the embodiments of the present application, the similarity between the address string and the byte stream can be accurately determined according to the comparison parameter of the address string and the byte stream, so as to accurately determine the IP address corresponding to the reverse tracing demand information from the tracing database.
[0094] In one design, the initial training parameter includes: the training parameter of the current iteration training input and the historical maximum training parameter; as shown in FIG. 7, in the information reverse tracing method provided by the embodiments of the present application, S503 can specifically include S701. Figure 7
[0095] S701. During each iteration of training, based on the training parameters input in the current iteration and the historical maximum training parameters, the training parameters after the current iteration are determined by a semi-supervised learning algorithm.
[0096] It can be understood that the training parameters of the current iteration training input include: the source tracing accuracy of the current iteration training input, the source tracing path completeness of the current iteration training input, and the source tracing analysis efficiency of the current iteration training input; the historical maximum training parameters include: the historical maximum source tracing accuracy, the historical maximum source tracing path completeness, and the historical maximum source tracing analysis efficiency.
[0097] That is, the training parameters input for the first training iteration include: initial source tracing accuracy, initial source tracing path completeness, and initial source tracing analysis efficiency; the training parameters input for the Kth training iteration include: the source tracing accuracy obtained from the previous training iteration, the source tracing path completeness obtained from the previous training iteration, and the source tracing analysis efficiency obtained from the previous training iteration. The historical maximum training parameter is the largest training parameter obtained from the previous K training iterations.
[0098] Optionally, during the first iteration of training, the initial training parameters (i.e., the initial source tracing accuracy) can be used as a basis. Initial source tracing path completeness rate Initial source analysis efficiency The training parameters after the first iteration of training are determined as follows: first source tracing accuracy. First source tracing path completeness rate First source tracing analysis efficiency Then, the training parameters after the Kth iteration are: Kth source tracing accuracy. Completeness of the Kth source tracing path Kth source tracing analysis efficiency
[0099] For example, a semi-supervised learning algorithm is shown in Formula 4:
[0100]
[0101] in, Accuracy can be determined by traceability Source tracing path completeness rate Source tracing analysis efficiency The result is shown in Formula 5:
[0102]
[0103] and, This is a semi-supervised learning factor, which can be specifically determined using Formula 6.
[0104]
[0105] wherein, is the semi-supervised learning factor corresponding to the kth iteration, respectively, the historical maximum trace path integrity rate, the historical maximum trace accuracy rate, and the historical maximum trace analysis efficiency in the current iteration training.
[0106] In the embodiments of the present application, after each iteration training, the latest training parameters can be determined, so that in the next iteration training, the IP address corresponding to the reverse trace demand information can be more accurately determined from the trace database based on the latest training parameters.
[0107] In one design, as shown in Figure 8 the S402 in the information reverse trace method provided by the embodiments of the present application can specifically include S801-S802.
[0108] S801, after each iteration training, if the training parameters after iteration training meet the preset conditions, the next iteration training is started.
[0109] wherein, the training parameter evaluation algorithm is used to determine whether the training parameters meet the training conditions.
[0110] For example, the training parameter evaluation algorithm is shown in Equation Seven:
[0111]
[0112] It can be understood that through the training parameter evaluation algorithm, it can be determined whether the training parameters meet the preset conditions after each iteration training, so as to determine whether to continue iteration training.
[0113] S802, based on the training parameters after the last iteration training, the next iteration training is performed on the reverse trace model, and if the number of iteration training reaches the preset number, the IP address determined from the trace database in the last iteration training is taken as the IP address of the attacker corresponding to the reverse trace demand information.
[0114] It can be understood that when the iteration training reaches the preset number, the iteration training is stopped, and the IP address finally determined from the trace database is taken as the IP address of the attacker corresponding to the reverse trace demand information.
[0115] Optionally, after multiple iteration training, a large amount of data information can be obtained, as shown in Figure 9 a data storage model provided by the embodiments of the present application, after the preset number of iteration training, the data information obtained after each iteration training can be stored through the data storage model.
[0116] In the embodiments of the present application, after each iteration training, it can be determined whether the training parameters after iteration training meet the preset condition through a training parameter evaluation algorithm, so that the next iteration training is started when the training parameters after iteration training meet the preset condition, thereby improving the efficiency of iteration training.
[0117] The above mainly introduces the scheme provided by the embodiments of the present application from the perspective of method. In order to realize the above functions, it contains the hardware structure and / or software module corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed in the present application, the embodiments of the present application can be realized in the form of hardware or the combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0118] The embodiments of the present application can divide the functional modules of an information reverse tracing device according to the above method examples. For example, each functional module can be divided according to each function, or two or more functions can be integrated in one processing module. The above integrated module can be realized in the form of hardware or software functional module. Optionally, the division of the module in the embodiments of the present application is illustrative, and is only a logical functional division. In actual implementation, there can be another division method.
[0119] Figure 10 The structural schematic diagram of an information reverse tracing device provided by the embodiments of the present application is shown in FIG. 1, which is an information reverse tracing device 100 for improving the efficiency of analyzing the information related to attack behavior and improving network security, for example, for executing the information reverse tracing method shown in FIG. 2. Figure 10 Figure 2 As shown in FIG. 1, the information reverse tracing device 100 includes an acquisition unit 1001 and a processing unit 1002.
[0120] The acquisition unit 1001 is configured to acquire reverse tracing demand information. The reverse tracing demand information is attack information determined when a network is attacked. The reverse tracing demand information includes at least one of the following: a data flow direction, a source IP address, a destination IP address, a data propagation state, a next-hop IP address, and an attack time. The processing unit 1002 is configured to input the reverse tracing demand information into a reverse tracing model, and determine an IP address of an attacker corresponding to the reverse tracing demand information from a tracing database. The reverse tracing model is configured to perform data analysis and processing on the reverse tracing demand information. The data analysis and processing includes at least one of the following: data collection, data filtering, data cleaning, attack behavior detection, and IP address tracing. The tracing database includes a plurality of byte streams. Each byte stream includes a plurality of byte data.
[0121] In a possible implementation, the processing unit 1002 is specifically configured to construct a sparse matrix based on the reverse tracing demand information. The sparse matrix is used to represent the reverse tracing demand information. The processing unit 1002 is specifically configured to input the sparse matrix into the reverse tracing model, and determine the IP address of the attacker corresponding to the reverse tracing demand information from the tracing database.
[0122] In a possible implementation, the processing unit 1002 is specifically configured to input the reverse tracing demand information and initial training parameters into the reverse tracing model, and perform multiple iteration training on the reverse tracing model. An output result of each iteration training includes an IP address determined from the tracing database and a training parameter after iteration training. The initial training parameters include: an initial tracing accuracy, an initial tracing path integrity, and an initial tracing analysis efficiency. The processing unit 1002 is specifically configured to, in a case where the iteration training is performed for a preset number of times and the training parameter after each iteration training meets a preset condition, determine, as the IP address of the attacker corresponding to the reverse tracing demand information, the IP address determined from the tracing database in the last iteration training.
[0123] In a possible implementation, the processing unit 1002 is specifically configured to analyze the reverse tracing demand information to obtain a plurality of address strings. Each address string in the plurality of address strings includes a plurality of bytes. The processing unit 1002 is specifically configured to compare the plurality of address strings with a plurality of byte streams included in the tracing database, determine the IP address corresponding to the reverse tracing demand information from the tracing database, and determine the training parameter after iteration training based on the initial training parameter.
[0124] In a possible implementation, the processing unit 1002 is specifically configured to, for any one address string and any one byte stream, determine a comparison parameter of the any one address string and the any one byte stream based on a byte comparison algorithm. The processing unit 1002 is specifically configured to determine the IP address corresponding to the reverse tracing demand information from the tracing database based on the comparison parameter of each address string and each byte stream.
[0125] In a possible implementation, the processing unit 1002 is specifically configured to determine the training parameter after each iteration training based on the training parameter input in the current iteration training and the historical maximum training parameter by using a semi-supervised learning algorithm.
[0126] In a possible implementation, the processing unit 1002 is specifically configured to start the next iteration training when the training parameter after the iteration training meets the preset condition by using a training parameter evaluation algorithm, and the training parameter evaluation algorithm is used to determine whether the training parameter meets the training condition. The processing unit 1002 is specifically configured to perform the next iteration training on the reverse tracing model based on the training parameter after the last iteration training, and determine the IP address of the attacker corresponding to the reverse tracing requirement information as the IP address of the attacker corresponding to the reverse tracing requirement information from the tracing database when the number of iteration training reaches the preset number.
[0127] In the case of implementing the functions of the above integrated modules in the form of hardware, the embodiment of the present application provides another possible structural diagram of the electronic device involved in the above embodiment. As shown in Figure 11 An electronic device 110 is used to improve the efficiency of analyzing the information related to the attack behavior, improve the network security, and for example, is used to perform Figure 2 An information reverse tracing method as shown in. The electronic device 110 includes a processor 1101, a memory 1102 and a bus 1103. The processor 1101 and the memory 1102 can be connected through the bus 1103.
[0128] The processor 1101 is the control center of the communication device, which can be one processor or a plurality of processing elements. For example, the processor 1101 can be a general central processing unit (CPU), or other general-purpose processors, etc. The general-purpose processor can be a microprocessor or any conventional processor.
[0129] As an embodiment, the processor 1101 can include one or more CPUs, such as the CPU 0 and the CPU 1 shown in Figure 11 As an embodiment, the processor 1101 can include one or more CPUs, such as the CPU 0 and the CPU 1 shown in
[0130] The memory 1102 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM), or other type of dynamic storage device that can store information and instructions for execution by the processor 1101, an electrically erasable programmable read-only memory (EEPROM), a magnetic disk storage medium, or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto.
[0131] As one possible implementation, the memory 1102 can exist independently of the processor 1101, and the memory 1102 can be connected to the processor 1101 through the bus 1103 for storing instructions or program code. When the processor 1101 invokes and executes the instructions or program code stored in the memory 1102, the information reverse tracing method provided by the embodiments of the present application can be implemented.
[0132] In another possible implementation, the memory 1102 can also be integrated with the processor 1101.
[0133] The bus 1103 can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, Figure 11 Only one thick line is used to represent the bus in the figure, but it does not mean that there is only one bus or only one type of bus.
[0134] It should be noted that Figure 11 The structure shown does not constitute a limitation on the electronic device 110. In addition to Figure 11 The electronic device 110 can include more or fewer components than shown, or combine certain components, or different component arrangements.
[0135] As one example, the functions implemented by the acquisition unit 1001 and the processing unit 1002 in the information reverse tracing apparatus 100 are the same as the functions of the processor 1101 in the Figure 10 Figure 11
[0136] Optionally, as shown in Figure 11 The electronic device 110 provided by the embodiments of the present application can further include a communication interface 1104.
[0137] The communication interface 1104 is configured to connect with other devices through a communication network. The communication network can be an Ethernet, a wireless access network, a wireless local area network (WLAN), etc. The communication interface 1104 can include a receiving unit configured to receive data, and a sending unit configured to send data.
[0138] In one design, the communication interface in the electronic device provided by the embodiments of the present application can be integrated in the processor.
[0139] From the above description of the embodiments, those skilled in the art can clearly understand that, for the convenience and brevity, only the division of the above functional units is exemplified. In actual application, the above functions can be completed by different functional units according to needs, that is, the internal structure of the device is divided into different functional units to complete all or part of the functions described above. The specific working process of the above-described system, device and unit can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0140] The embodiments of the present application further provide a computer readable storage medium, and the computer readable storage medium stores instructions. When a computer executes the instructions, the computer executes each step in the method flow shown in the foregoing method embodiments.
[0141] The embodiments of the present application provide a computer program product containing instructions, which, when executed on a computer, cause the computer to execute an information reverse tracing method in the foregoing method embodiments.
[0142] The computer readable storage medium, for example, can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), registers, a hard disk, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. The computer readable storage medium can be any tangible medium that is capable of storing programming for use by or in connection with an instruction execution system, apparatus, or device.
[0143] An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. Of course, the storage medium can be a part of the processor. The processor and the storage medium can be located in an Application Specific Integrated Circuit (ASIC).
[0144] In the embodiments of the present application, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus or device.
[0145] Since the electronic device, the computer readable storage medium and the computer program product in the embodiments of the present application can be applied to the above method, the technical effects they can obtain can also be referred to the above method embodiments, and the embodiments of the present application will not be repeated here.
[0146] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application.
Claims
1. A method for reverse information tracing, characterized in that, The method includes: Obtain reverse tracing requirement information, which is attack information determined when the network is attacked. The reverse tracing requirement information includes at least one of the following: data flow direction, source IP address, destination IP address, data propagation status, next-hop IP address, and attack time. The reverse tracing requirement information is input into the reverse tracing model, and the IP address of the attacker corresponding to the reverse tracing requirement information is determined from the tracing database. The reverse tracing model is used to perform data analysis and processing on the reverse tracing requirement information. The data analysis and processing includes at least one of the following: data collection, data filtering, data cleaning, attack behavior detection, and IP address tracing. The tracing database includes multiple byte streams, and each byte stream includes multiple bytes of data. The step of inputting the reverse tracing requirement information into the reverse tracing model and determining the IP address of the attacker corresponding to the reverse tracing requirement information from the tracing database includes: A sparse matrix is constructed based on the reverse tracing requirement information, and the sparse matrix is used to represent the reverse tracing requirement information; The sparse matrix is input into the reverse tracing model to determine the IP address of the attacker corresponding to the reverse tracing requirement information from the tracing database; The step of inputting the reverse tracing requirement information into the reverse tracing model and determining the IP address of the attacker corresponding to the reverse tracing requirement information from the tracing database also includes: The reverse tracing requirement information and initial training parameters are input into the reverse tracing model, and the reverse tracing model is trained iteratively multiple times. The output of each iteration includes the IP address determined from the tracing database and the training parameters after the iteration. The initial training parameters include: initial tracing accuracy, initial tracing path completeness, and initial tracing analysis efficiency. After a preset number of iterations of training, and provided that the training parameters after each iteration meet the preset conditions, the IP address determined from the source tracing database in the last iteration of training is used as the IP address of the attacker corresponding to the reverse source tracing requirement information.
2. The method according to claim 1, characterized in that, The step of inputting the reverse tracing requirement information and initial training parameters into the reverse tracing model and performing multiple iterations of training on the reverse tracing model includes: The reverse tracing requirement information is parsed to obtain multiple address strings, each of which includes multiple bytes. The multiple address strings are compared with the multiple byte streams included in the traceability database to determine the IP address corresponding to the reverse traceability requirement information from the traceability database, and the training parameters after iterative training are determined based on the initial training parameters.
3. The method according to claim 2, characterized in that, The step of comparing the multiple address strings with multiple byte streams included in the tracing database to determine the IP address corresponding to the reverse tracing requirement information from the tracing database includes: For any address string and any byte stream, the comparison parameters of the address string and the byte stream are determined based on a byte comparison algorithm; Based on the comparison parameters of each address string and each byte stream, the IP address corresponding to the reverse tracing requirement information is determined from the tracing database.
4. The method according to claim 2, characterized in that, The initial training parameters include: the training parameters input in the current iteration of training and the historical maximum training parameters; The process of determining the training parameters after iterative training based on the initial training parameters includes: During each iteration of training, the training parameters after the current iteration are determined by a semi-supervised learning algorithm based on the training parameters input for the current iteration and the historical maximum training parameters.
5. The method according to claim 1, characterized in that, The step of using the IP address determined from the source tracing database in the last iteration of training, after a preset number of training iterations and with the training parameters meeting preset conditions, as the IP address of the attacker corresponding to the reverse source tracing requirement information, includes: After each iteration of training, if the training parameters after the iteration meet the preset conditions through the training parameter evaluation algorithm, the next iteration of training will begin. The training parameter evaluation algorithm is used to determine whether the training parameters meet the training conditions. The reverse tracing model is trained again based on the training parameters after the previous iteration. When the number of iterations reaches a preset number, the IP address determined from the tracing database in the last iteration is used as the IP address of the attacker corresponding to the reverse tracing requirement information.
6. An information reverse tracing device, characterized in that, The information reverse tracing device includes: an acquisition unit and a processing unit; The acquisition unit is used to acquire reverse tracing requirement information, which is attack information determined when the network is attacked. The reverse tracing requirement information includes at least one of the following: data flow direction, source IP address, destination IP address, data propagation status, next-hop IP address, and attack time. The processing unit is used to input the reverse tracing requirement information into the reverse tracing model, determine the IP address of the attacker corresponding to the reverse tracing requirement information from the tracing database, and the reverse tracing model is used to perform data analysis processing on the reverse tracing requirement information. The data analysis processing includes at least one of the following: data collection, data filtering, data cleaning, attack behavior detection, and IP address tracing. The tracing database includes multiple byte streams, and each byte stream includes multiple bytes of data. The processing unit is specifically used to construct a sparse matrix based on the reverse tracing requirement information, and the sparse matrix is used to represent the reverse tracing requirement information. The processing unit is specifically used to input the sparse matrix into the reverse tracing model and determine the IP address of the attacker corresponding to the reverse tracing requirement information from the tracing database. The processing unit is specifically used to input the reverse tracing requirement information and initial training parameters into the reverse tracing model, and to perform multiple iterations of training on the reverse tracing model. The output of each iteration includes the IP address determined from the tracing database and the training parameters after the iteration. The initial training parameters include: initial tracing accuracy, initial tracing path completeness, and initial tracing analysis efficiency. The processing unit is specifically used to, after a preset number of iterations of training and when the training parameters after each iteration meet the preset conditions, use the IP address determined from the source tracing database in the last iteration of training as the IP address of the attacker corresponding to the reverse source tracing requirement information.
7. An electronic device, characterized in that, include: A processor and a memory; wherein the memory is used to store one or more programs, the one or more programs including computer execution instructions, and when the electronic device is running, the processor executes the computer execution instructions stored in the memory to cause the electronic device to perform an information reverse tracing method according to any one of claims 1-5.
8. A computer-readable storage medium for storing one or more programs, characterized in that, The one or more programs include instructions that, when executed by a computer, cause the computer to perform an information reverse tracing method as described in any one of claims 1-5.
Citation Information
Patent Citations
Attack tracing method and device, electronic equipment and storage medium
CN111193749A
Network attack event traceability processing method and device, equipment and storage medium
CN111935192A