An intelligent network traffic analysis and intrusion detection method

By analyzing the log information of the network system and the historical and real-time behavior characteristics of the access nodes, combining data throughput prediction, and calculating the data abnormal risk value of the network system, the problem of lack of pre-identification and monitoring in the existing technology is solved, and the risk identification and data security of the network system is improved.

CN118842642BActive Publication Date: 2025-06-17SHAANXI YUNQI WEIMIAN TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411066058.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-05
Publication Date
2025-06-17
Estimated Expiration
2044-08-05

AI Technical Summary

Technical Problem

The prior art lacks pre-identification monitoring in network intrusion detection, making it difficult to build a risk assessment plan for network systems, resulting in data security risks in network systems.

Method used

By retrieving the log information of the network system, obtaining the historical access behavior feature library and real-time access behavior characteristics of the access node, using an exception recognition algorithm to determine whether there are abnormalities in the access behavior, and combining historical data throughput to predict the standard data throughput, calculate the data abnormality risk value of the network system.

Benefits of technology

It realizes pre-identification and monitoring of risks of the network system, and can identify hijacked access nodes that have not made risk access identification behaviors, reduces data security risks of the network system, and improves the security of the network system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118842642B_ABST
    Figure CN118842642B_ABST
Patent Text Reader

Abstract

The present invention discloses an intelligent network traffic analysis and intrusion detection method, which relates to the technical field of network evaluation, and includes: retrieving the log information of the network system; obtaining at least one access node accessing the network system; determining the historical access behavior feature library of each access node, and extracting and analyzing the normal access behavior information of each access node; obtaining in real time the access behavior of the access node in the network system, and extracting the access behavior features as real-time access behavior features; using an anomaly recognition algorithm to determine whether there is an anomaly in this access behavior; predicting the standard data throughput of the access node based on the historical data throughput status of the access node; calculating the data anomaly risk value of the current network system, and determining whether the data anomaly risk value is greater than a preset value. The advantages of the present invention are: realizing the pre-identification and monitoring of network risks, effectively reducing the data security hidden dangers of the network system, and improving the security of the network system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network evaluation, and more particularly to an intelligent network traffic analysis and intrusion detection method. Background Art

[0002] With the development of communication network technology, more and more data depends on communication networks for transmission. Based on this, real-time analysis and evaluation of the security risks of communication networks is an important part of maintaining the efficient and secure operation of communication networks. However, in the prior art, when performing network intrusion detection, a risk access recognition behavior monitoring method is adopted, that is, when a risk access recognition behavior that is harmful to the communication network is detected in an access node, a response is made. This monitoring method has a delay. For access nodes that have been hijacked but have not performed risk access recognition behaviors, there is a lack of pre-identification monitoring, and it is difficult to construct a pre-risk assessment plan for the network system, resulting in potential data security hazards in the network system. Summary of the Invention

[0003] To solve the above technical problems, an intelligent network traffic analysis and intrusion detection method is provided. The present technical solution solves the problem in the above prior art that in network intrusion detection, there is a lack of pre-identification monitoring, it is difficult to construct a pre-risk assessment plan for the network system, resulting in potential data security hazards in the network system.

[0004] To achieve the above object, the technical solution adopted by the present invention is as follows:

[0005] An intelligent network traffic analysis and intrusion detection method, comprising:

[0006] Retrieving the log information of the network system;

[0007] Obtaining at least one access node accessing the network system;

[0008] Determining the historical access behavior feature library of each access node based on the log information of the network system, and extracting and analyzing the normal access behavior information of each access node;

[0009] Real-time obtaining the access behavior of the access node in the network system, and extracting the access behavior feature and recording it as the real-time access behavior feature;

[0010] Based on the real-time access behavior feature and the normal access behavior information, using an anomaly recognition algorithm to determine whether there is an anomaly in this access behavior. If so, an anomaly value is added to the access node. If not, no response is made;

[0011] Based on the log information of the network system, determining the historical data throughput of each access node, and predicting the standard data throughput of the access node based on the historical data throughput status of the access node;

[0012] Calculate the data anomaly risk value of the current network system, and determine whether the data anomaly risk value is greater than a preset value. If so, it is determined that there is a data anomaly risk in the current network system; if not, it is determined that there is no data anomaly risk in the current network system.

[0013] Preferably, determining the historical access behavior feature library of each access node based on the log information of the network system, and extracting and analyzing the normal access behavior information of each access node specifically includes:

[0014] Record the historical access behavior feature library of the access node as A, , where, is the i-th historical access behavior feature corresponding to the access node, is the total number of historical access behavior features corresponding to the access node;

[0015] Adopt the feature correlation algorithm to determine the correlation degree between any two historical access behavior features in the historical access behavior feature library;

[0016] Record the correlation degree between all historical access behavior features of the access node as the normal access behavior information of the access node.

[0017] Preferably, the feature correlation algorithm is specifically:

[0018] Record the historical access behavior features for which the correlation degree needs to be calculated as and ;

[0019] Determine the total number of historical access behaviors in which appears, the total number of historical access behaviors in which appears, and the total number of historical access behaviors in which both and appear in the historical access behavior of the access node;

[0020] Calculate the correlation degree between and through the correlation calculation formula;

[0021] The specific correlation calculation formula is:

[0022]

[0023] In the formula, is the correlation degree between and , is the total number of historical access behaviors of the access node, is the total number of historical access behaviors in which appears in the historical access behavior of the access node, For the total number of historical access behaviors that appear in the historical access behaviors of the access node, For the total number of historical access behaviors that simultaneously appear in the historical access behaviors of the access node, and

[0024] Preferably, the anomaly recognition algorithm is specifically:

[0025] Combine all real-time access behavior features in pairs to form a number of real-time access behavior feature groups;

[0026] Retrieve the real-time access behavior feature groups in the normal access behavior information. If the correlation between the corresponding historical access behavior features can be retrieved, use this correlation as the access index for this real-time access behavior feature group. If the correlation between the corresponding historical access behavior features cannot be retrieved, assign a value of 0 to the access index of this real-time access behavior feature group;

[0027] Take the average value of the access indexes of all real-time access behavior feature groups to obtain the access index of this access behavior;

[0028] Determine whether the access index of this access behavior is greater than the standard access index of the access node. If so, determine that this access behavior has no anomaly. If not, determine that this access behavior has an anomaly;

[0029] For an access behavior with an anomaly, calculate the difference between the access index of the access behavior and the standard access index of the access node as the anomaly value of this access behavior.

[0030] Preferably, the process of obtaining the standard access index of the access node is:

[0031] Set a statistical duration;

[0032] Obtain all the historical access behaviors of the access node within the recent statistical duration, denoted as sample access behaviors;

[0033] Calculate the access index of each sample access behavior respectively, and find the average value of the access indexes of all sample access behaviors as the standard access index of the access node.

[0034] Preferably, determining the historical data throughput of the access node based on the log information of the network system and predicting the standard data throughput of the access node based on the historical data throughput status of the access node specifically includes:

[0035] Set a data throughput statistical period;

[0036] ​​Obtain the total historical data throughput of the access nodes in several data throughput statistical periods closest to the current one, denoted as the total sample data throughput;

[0037] Construct an outlier rejection formula based on the Grubbs criterion;

[0038] Based on the outlier rejection formula, eliminate the outliers in several total sample data throughputs to obtain several standard total sample data throughputs;

[0039] Calculate the average of all standard total sample data throughputs as the standard data throughput of the access node;

[0040] Among them, the outlier rejection formula is specifically:

[0041] ;

[0042] In the formula, is the j-th total sample data throughput, is the average of all total sample data throughputs, is the standard deviation of all total sample data throughputs; is the total number of all total sample data throughputs, is the significance level the value of the t-distribution at, is the detection level in the Grubbs criterion.

[0043] Preferably, the specific method for calculating the data anomaly risk value of the current network system is:

[0044] Determine the cumulative value of the outliers of each access node in the network system within the statistical duration, denoted as the total anomaly value of the access node;

[0045] Based on the total anomaly value of the access node and the access node, calculate the data anomaly risk value of the network system through the risk calculation formula;

[0046] The risk calculation formula is specifically:

[0047] ;

[0048] In the formula, is the data anomaly risk value of the network system, is the total anomaly value of the g-th access node, is the standard data throughput of the g-th access node, is the total number of access nodes accessing the network system.

[0049] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0050] The present invention proposes an intelligent network traffic analysis and intrusion detection solution, which dynamically learns and analyzes based on the historical access behavior logs of each access node, constructs the normal access behavior information of the access node under normal conditions, and performs anomaly recognition on the access behavior of the access node based on the normal access behavior information of the access node under normal conditions. For the access behavior that does not conform to the access node under normal conditions, an outlier is attached, and the risk of the entire network system is evaluated by combining the outliers of the access node in the short term and the data throughput of the access node. In this way, when the access node of the network system is hijacked, even if it does not perform a risk access recognition behavior, the abnormal access behavior existing in it can still be recognized, thereby realizing the pre-identification and monitoring of network risks, and data protection measures can be taken before the hijacked access node makes a risk access recognition behavior, which can effectively reduce the data security hidden danger of the network system and improve the security of the network system. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 It is a flowchart of the intelligent network traffic analysis and intrusion detection method proposed by the present invention;

[0052] Figure 2 It is a flowchart of the method for extracting and analyzing the normal access behavior information of each access node in the present invention;

[0053] Figure 3 It is a flowchart of the feature correlation algorithm in the present invention;

[0054] Figure 4 It is a flowchart of the anomaly recognition algorithm in the present invention;

[0055] Figure 5 It is a flowchart of the method for obtaining the standard access metrics of the access node in the present invention;

[0056] Figure 6 It is a flowchart of the method for predicting the standard data throughput of the access node in the present invention;

[0057] Figure 7 It is a flowchart of the method for calculating the data anomaly risk value of the current network system in the present invention;

[0058] Figure 8 It is a schematic structural diagram of the electronic device of the present invention;

[0059] Figure 9 It is a schematic structural diagram of the computer-readable storage medium of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0060] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments described below are only examples, and those skilled in the art can think of other obvious variations.

[0061] Referring to Figure 1 as shown, an intelligent network traffic analysis and intrusion detection method includes:

[0062] Retrieving the log information of the network system;

[0063] Obtaining at least one access node accessing the network system;

[0064] Based on the log information of the network system, determining the historical access behavior feature library of each access node, and extracting and analyzing the normal access behavior information of each access node;

[0065] Obtaining in real time the access behavior of the access node in the network system, and extracting the access behavior features and recording them as real-time access behavior features;

[0066] Based on the real-time access behavior features and the normal access behavior information, using an anomaly recognition algorithm to determine whether there is an anomaly in this access behavior. If so, attaching an anomaly value to the access node. If not, no response is made;

[0067] Based on the log information of the network system, determining the historical data throughput of each access node, and predicting the standard data throughput of the access node based on the historical data throughput status of the access node;

[0068] Calculating the data anomaly risk value of the current network system, and determining whether the data anomaly risk value is greater than a preset value. If so, determining that there is a data anomaly risk in the current network system. If not, determining that there is no data anomaly risk in the current network system.

[0069] This solution conducts dynamic learning and analysis based on the historical access behavior logs of each access node, constructs the normal access behavior information of the access node under normal conditions, and conducts anomaly recognition on the access behavior of the access node based on the normal access behavior information of the access node under normal conditions. For the access behavior that does not conform to the access node under normal conditions, an anomaly value is attached, and the risk of the entire network system is evaluated by combining the anomaly values of the access node in the short term and the data throughput of the access node.

[0070] Referring to Figure 2 as shown, determining the historical access behavior feature library of each access node based on the log information of the network system, and extracting and analyzing the normal access behavior information of each access node specifically includes:

[0071] Denote the historical access behavior feature library of the access node as A, , where is the i-th historical access behavior feature corresponding to the access node, is the total number of historical access behavior features corresponding to the access node;

[0072] Use the feature correlation algorithm to determine the correlation degree between any two historical access behavior features in the historical access behavior feature library;

[0073] Record the correlation degree between all historical access behavior features of the access node as the normal access behavior information of the access node.

[0074] Refer to Figure 3 As shown, the feature correlation algorithm is specifically as follows:

[0075] Record the historical access behavior features for which the correlation degree needs to be calculated as and ;

[0076] Determine the total number of historical access behaviors in which appears, the total number of historical access behaviors in which appears, and the total number of historical access behaviors in which both and appear in the historical access behavior of the access node;

[0077] Calculate the correlation degree between and through the correlation calculation formula;

[0078] The correlation calculation formula is specifically as follows:

[0079] ;

[0080] In the formula, is the correlation degree between and , is the total number of historical access behaviors of the access node, is the total number of historical access behaviors in which appears in the historical access behavior of the access node, is the total number of historical access behaviors in which appears in the historical access behavior of the access node, is the total number of historical access behaviors in which both and appear in the historical access behavior of the access node.

[0081] In this solution, the calculation correlation formula consists of two parts. One part is the occurrence frequency in the access behaviors corresponding to and , that is, , which represents the rationality of the occurrence of and in the access behaviors of the access node in the normal state. The other part is and The rationality that appears simultaneously in the same behavior, that is , this part represents the access behavior of the access node in the normal state and When they appear simultaneously, the normality is calculated by combining the appearance of the access node and The rationality of and and When they appear simultaneously, calculate the normality and and The correlation between them. The larger the value of the correlation, the higher the correlation between and .

[0082] Refer to Figure 4 As shown, the abnormal recognition algorithm is specifically as follows:

[0083] Combine all real-time access behavior characteristics in pairs to form several real-time access behavior characteristic groups;

[0084] Retrieve the real-time access behavior characteristic groups in the normal access behavior information. If the correlation between the corresponding historical access behavior characteristics can be retrieved, use this correlation as the access index of this real-time access behavior characteristic group. If the correlation between the corresponding historical access behavior characteristics cannot be retrieved, assign a value of 0 to the access index of this real-time access behavior characteristic group;

[0085] Take the average value of the access indexes of all real-time access behavior characteristic groups to obtain the access index of this access behavior;

[0086] Judge whether the access index of this access behavior is greater than the standard access index of the access node. If so, determine that this access behavior has no abnormality. If not, determine that this access behavior has an abnormality;

[0087] For the access behavior with an abnormality, calculate the difference between the access index of the access behavior and the standard access index of the access node as the abnormal value of this access behavior.

[0088] By combining the real-time access behavior characteristics in pairs to form several real-time access behavior characteristic groups, and comprehensively calculating the access index of the access node during the access action based on the correlation between the real-time access behavior characteristic groups, the larger the access index, the more in line with the historical access habits of the access node when the access node is performing the current access behavior, and the safer this access behavior is.

[0089] Refer to Figure 5 As shown, the process of obtaining the standard access index of the access node is as follows:

[0090] Set a statistical duration;

[0091] Obtain all historical access behaviors of the access node within the most recent statistical duration, and record them as sample access behaviors;

[0092] Calculate the access metrics of each sample access behavior respectively, and find the average value of the access metrics of all sample access behaviors as the standard access metric of the access node.

[0093] It can be understood that the access behavior of the access node is not static, and the access behavior of the access node has periodic changes. Based on this, this solution realizes the dynamic state update of the access node by designing the statistical duration and calculating the standard access metric of the access node within the statistical duration.

[0094] Refer to Figure 6 As shown, based on the log information of the network system, determining the historical data throughput of the access node and predicting the standard data throughput of the access node based on the historical data throughput status of the access node specifically includes:

[0095] Set a data throughput statistical period;

[0096] Obtain the total historical data throughput of the access node within several data throughput statistical periods closest to the current one, and record it as the total sample data throughput;

[0097] Construct an outlier rejection formula based on the Grubbs criterion;

[0098] Based on the outlier rejection formula, eliminate the outliers in several total sample data throughputs to obtain several standard total sample data throughputs;

[0099] Find the average value of all standard total sample data throughputs as the standard data throughput of the access node;

[0100] Among them, the outlier rejection formula is specifically:

[0101] ;

[0102] In the formula, is the total sample data throughput of the jth one, is the average value of all total sample data throughputs, is the standard deviation of all total sample data throughputs; is the total number of all total sample data throughputs, is the significance level the value of the t-distribution under, is the detection level in the Grubbs criterion.

[0103] It is understandable that during the operation of the network system, it is usually affected by some unexpected events, resulting in an abnormal increase or decrease in the data throughput of the access nodes. The impact of these unexpected events will cause a large error in the standard data throughput of the access nodes. To eliminate these deviation points, in this solution, based on the Grubbs test algorithm, the data throughput generated by unexpected events is identified and calculated, and the outlier points are eliminated, thereby effectively improving the calculation accuracy of the standard data throughput of the access nodes.

[0104] Refer to Figure 7 As shown, the specific method for calculating the data anomaly risk value of the current network system is as follows:

[0105] Determine the cumulative value of the anomaly values of each access node in the network system within the statistical duration, denoted as the total anomaly value of the access node;

[0106] Based on the total anomaly value of the access node and the access node, calculate the data anomaly risk value of the network system through the risk calculation formula;

[0107] The specific risk calculation formula is:

[0108]

[0109] In the formula, is the data anomaly risk value of the network system, is the total anomaly value of the g-th access node, is the standard data throughput of the g-th access node, is the total number of access nodes accessing the network system.

[0110] By calculating the cumulative value of the anomaly values of the access nodes in the entire network system and the data throughput of the access nodes, the anomaly risk value of the network system is comprehensively calculated. The larger the data anomaly risk value, the more data with large traffic passes through the access nodes with high anomaly values in the entire network system. At this time, the entire network system is at high risk.

[0111] Furthermore, the method according to the embodiment of the present application can also be implemented with the help of Figure 8 the architecture of the electronic device shown. As Figure 8 shown, the electronic device 500 may include a bus 501, one or more CPUs 502, a read-only memory (ROM) 503, a random access memory (RAM) 504, a communication port 505 connected to the network, an input / output component 506, a hard disk 507, etc. The storage device in the electronic device 500, such as the ROM 503 or the hard disk 507, can store the intelligent network traffic analysis and intrusion detection method provided by the present application. The electronic device 500 may also include a user interface 508. Of course, Figure 8The architecture shown is only exemplary. When implementing different devices, one or more components in the Figure 8 Figure 8 shown electronic device may be omitted according to actual needs.

[0112] Figure 9 It is a schematic structural diagram of a computer-readable storage medium provided by an embodiment of the present application. As Figure 9 shown, it is a computer-readable storage medium 600 according to an embodiment of the present application. Computer-readable instructions are stored on the computer-readable storage medium 600. When the computer-readable instructions are run by a processor, the intelligent network traffic analysis and intrusion detection method according to the embodiment of the present application described with reference to the above drawings can be executed. The storage medium 600 includes, but is not limited to, for example, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and cache memory, etc. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0113] In summary, the advantages of the present invention are as follows: realizing the pre-identification and monitoring of network risks, effectively reducing the data security risks of the network system, and improving the security of the network system.

[0114] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.

Claims

1. An intelligent network traffic analysis and intrusion detection method, characterized in that: include: Retrieve the log information of the network system; Acquire at least one access node for accessing the network system; Determine the historical access behavior feature library of each access node based on the log information of the network system, and extract and analyze the normal access behavior information of each access node; Acquire the access behavior of the access node in the network system in real time, and extract the access behavior features and record them as real-time access behavior features; Based on the real-time access behavior characteristics and normal access behavior information, an abnormal identification algorithm is used to determine whether the access behavior is abnormal. If so, an abnormal value is added to the access node. If not, no response is made. Based on the log information of the network system, determine the historical data throughput of each access node, and predict the standard data throughput of the access node based on the historical data throughput status of the access node; Calculate the data anomaly risk value of the current network system, and determine whether the data anomaly risk value is greater than a preset value. If so, determine that the current network system has data anomaly risk; if not, determine that the current network system does not have data anomaly risk; The method of determining the historical access behavior feature library of each access node based on the log information of the network system and extracting and analyzing the normal access behavior information of each access node specifically includes: The historical access behavior feature library of the access node is recorded as A. ,in, is the i-th historical access behavior feature corresponding to the access node, is the total number of historical access behavior features corresponding to the access node; Using feature correlation algorithm, determine the correlation between any two historical access behavior features in the historical access behavior feature library; The correlation between all historical access behavior features of the access node is recorded as the normal access behavior information of the access node; The feature correlation algorithm is specifically: The historical access behavior characteristics that need to be calculated are and ; Determine the historical access behavior of the access node. The total number of historical access behaviors and occurrences The total number of historical access behaviors and simultaneous occurrences and The total number of historical visit behaviors; Calculated by correlation formula and The correlation between The correlation calculation formula is specifically: ; In the formula, for and The correlation between is the total number of historical access behaviors of the access node, In the historical access behavior of the access node, The total number of historical visit behaviors, In the historical access behavior of the access node, The total number of historical visit behaviors, In the historical access behavior of the access node, and The total number of historical visit behaviors; The anomaly identification algorithm is specifically: All real-time access behavior features are combined in pairs into several real-time access behavior feature groups; The real-time access behavior feature group is searched in the normal access behavior information. If the correlation between the corresponding historical access behavior features can be retrieved, the correlation is used as the access index of the real-time access behavior feature group. If the correlation between the corresponding historical access behavior features cannot be retrieved, the access index of the real-time access behavior feature group is assigned a value of 0. The access index of all real-time access behavior feature groups is averaged to obtain the access index of the access behavior; Determine whether the access index of the access behavior is greater than the standard access index of the access node. If so, it is determined that there is no abnormality in the access behavior. If not, it is determined that there is an abnormality in the access behavior. For abnormal access behaviors, the difference between the access index of the access behavior and the standard access index of the access node is calculated as the abnormal value of this access behavior; The process of obtaining the standard access index of the access node is as follows: Set a statistical duration; Get all historical access behaviors of the node in the most recent statistical period and record them as sample access behaviors; Calculate the access index of each sample access behavior separately, and find the average of the access index of all sample access behaviors as the standard access index of the access node; The determining of the historical data throughput of the access node based on the log information of the network system and predicting the standard data throughput of the access node based on the historical data throughput status of the access node specifically includes: Set a data throughput statistics period; Obtain the total historical data throughput of the access node in several data throughput statistical periods closest to the current one, and record it as the total sample data throughput; Construct anomaly elimination formula based on Grubbs criterion; Based on the abnormal elimination formula, the abnormal values ​​in the total throughput of several sample data are eliminated to obtain the total throughput of several standard sample data; Calculate the average value of the total data throughput of all standard samples as the standard data throughput of the access node; The abnormal elimination formula is specifically: ; In the formula, is the total throughput of the jth sample data, is the average value of the total throughput of all sample data. is the standard deviation of the total throughput of all sample data; is the total number of total sample data throughput, The significant level The value of the t-distribution under is the detection level in the Grubbs criterion; The specific method for calculating the data anomaly risk value of the current network system is: Determine the accumulated value of abnormal values ​​of each access node in the network system within the statistical time period, and record it as the total abnormal value of the access node; Based on the total abnormal value of access nodes and access nodes, the data abnormal risk value of the network system is calculated through the risk calculation formula; The risk calculation formula is specifically: ; In the formula, is the data anomaly risk value of the network system, is the total abnormal value of the g-th visited node, is the standard data throughput of the g-th access node, is the total number of access nodes connected to the network system.

2. An electronic device, characterized in that: include: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the intelligent network traffic analysis and intrusion detection method as claimed in claim 1.

3. A computer-readable storage medium having a computer-readable program stored thereon, characterized in that: When the computer-readable program is executed by a processor, the intelligent network traffic analysis and intrusion detection method according to claim 1 is implemented.

Citation Information

Patent Citations

  • Connection state monitoring method and system based on communication network access of Internet of Things equipment

    CN117914742A