A comprehensive network security protection system based on deep learning

By introducing deep learning-based multi-level identification mechanism and multi-source data fusion in network security analysis, the problem of low efficiency and flexibility in traditional technologies is solved, and more accurate network traffic security analysis and higher network protection security are achieved.

CN118890187BActive Publication Date: 2025-05-06WUHAN ANYU INFORMATION SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411016621.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-29
Publication Date
2025-05-06
Estimated Expiration
2044-07-29

AI Technical Summary

Technical Problem

Traditional network traffic security analysis technology has low efficiency and flexibility, making it difficult to ensure the accuracy of traffic security analysis, thereby reducing network protection security.

Method used

A comprehensive network security protection system based on deep learning is adopted, including a primary security identification module and a deep learning detection module. The primary security identification module recognizes secure and malicious traffic through the primary and secondary recognition submodules, and the deep learning detection module uses abnormal character detection, multi-source data fusion and graph neural network submodules to identify potential threat chains and association strengths.

Benefits of technology

It realizes more accurate identification of secure and malicious traffic in network traffic, integrates multi-source data to improve abnormal pattern recognition, identify potential threat chains and association strength, and improves the accuracy and security of comprehensive network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118890187B_ABST
    Figure CN118890187B_ABST
Patent Text Reader

Abstract

The present invention relates to a network security comprehensive protection system based on deep learning, and the system comprises: a primary security identification module, which is used for performing security identification on network flow data; a deep learning detection module, which is used for receiving and identifying network flow data that cannot be determined by the primary security identification module; the abnormal character detection submodule is used for identifying characters with abnormal tendencies in network flow data; the multi-source data fusion submodule is used for acquiring auxiliary data sources and fusing them with network flow to form a comprehensive data stream; the graph neural network submodule is used for receiving the comprehensive data stream, constructing graph structure data according to the comprehensive data stream, acquiring the threat chain existing in the network flow data, calculating the correlation strength of the threat chain, and generating the total value of the threat chain correlation; the system can accurately discover the abnormal patterns that are not obvious in a single data source, improve the comprehensive network security protection capability, and achieve the effect of accurately evaluating the security of network flow data and the harm of the threat chain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data analysis and network security technology, and in particular to a network security comprehensive protection system based on deep learning. Background Art

[0002] Network traffic analysis is the process of recording and analyzing network traffic for the purpose of performance, security, network operation, management and troubleshooting. It is the process of using automatic technology to check detailed level details and statistical information in network traffic. As network security has received more and more attention, security analysis technologies for network traffic have emerged in an endless stream. However, traditional traffic security analysis technology solutions often have the defects of low efficiency and flexibility. The data source used in traffic analysis is single, which makes it difficult to ensure the accuracy of traffic security analysis, thereby reducing the security of network protection. Summary of the invention

[0003] In view of the technical problems existing in the prior art, the present invention provides a comprehensive network security protection system based on deep learning.

[0004] The technical solution of the present invention to solve the above technical problems is as follows: a network security integrated protection system based on deep learning, the system comprising: a primary security identification module, used to perform security identification on network traffic data, the security identification module comprising a primary identification submodule and a secondary identification submodule, the primary identification submodule is used to identify whether it is safe traffic, and the secondary identification submodule is used to identify whether it is malicious traffic;

[0005] A deep learning detection module is used to receive and identify network traffic data that cannot be determined by the primary security identification module; the deep learning detection module includes an abnormal character detection submodule, a multi-source data fusion submodule and a graph neural network submodule, the abnormal character detection submodule is used to identify characters with abnormal tendencies in network traffic data; the multi-source data fusion submodule is used to obtain auxiliary data sources and fuse them with network traffic to form a comprehensive data stream; the graph neural network submodule is used to receive the comprehensive data stream, construct graph structure data according to the comprehensive data stream, obtain the threat chain existing in the network traffic data, calculate the correlation strength of the threat chain, and generate the total value of the threat chain correlation;

[0006] The security confirmation protection module is used to determine whether the network traffic data is safe based on the total value of the threat chain association and generate an analysis report.

[0007] Furthermore, the deep learning detection module also includes a time series analysis submodule, which is used to receive a comprehensive data stream and establish a time series, generate a comprehensive data stream with time nodes, and classify the risk intentions of abnormal tendency characters in combination with the time nodes to generate a risk time set.

[0008] Furthermore, the time series analysis submodule receives the threat chain association value, classifies the threat chain association value according to the time nodes to generate an associated time set, combines the risk time set with the associated time set, and selects the overlapping time nodes as heavy abnormal nodes.

[0009] Furthermore, according to the data information of the heavy abnormal nodes, a sliding time window is set to perform in-depth re-inspection on the heavy abnormal nodes. The in-depth re-inspection is to define a time window with each heavy abnormal node as the center, and to perform in-depth re-inspection on the threat chain data and abnormal characters in the previous and next time windows. The threat chain association value is adjusted according to the result of the in-depth re-inspection, and the graph neural network sub-module generates a total threat chain association value according to the adjusted threat chain association value.

[0010] Furthermore, according to the results of the deep re-inspection, the data changes of the previous and next time windows are analyzed, and the trend of the change of the threat chain correlation value of the future time nodes is predicted with the current time node as the center, and the prediction results are transmitted to the graph neural network sub-module.

[0011] Furthermore, the deep learning detection module also includes a cross-domain analysis submodule, which is used to extract cross-domain data information based on heavy abnormal nodes and threat chains with cross-domain attacks, construct a cross-domain threat chain based on the cross-domain data analysis results, and generate a cross-domain threat index.

[0012] Furthermore, the cross-domain data analysis result is to identify similar related attack behaviors across domains, collect nodes and edges that frequently interact between different network domains, and generate a cross-domain threat chain based on cross nodes and edges; the cross-domain data analysis result is a comprehensive analysis of the cross-domain data flow formed by cross-domain data and comprehensive data flow.

[0013] Further, the cross-domain threat index is generated by combining a threat chain association value and a cross-domain threat chain association value, and the cross-domain threat chain association value is generated based on the cross-domain threat chain.

[0014] Furthermore, the deep re-inspection results of the heavy abnormal nodes and heavy abnormal nodes with cross-domain attacks are obtained, the periodicity and trend characteristics of the time nodes are obtained, the cross-domain data are classified according to the periodicity and trend characteristics of the time nodes, and cross-domain data of different classifications are cross-combined and analyzed to identify the similarity and correlation of abnormal characters between different network domains, and generate cross-analysis results.

[0015] Furthermore, the correlation strength of different cross-domain threat chains is calculated based on the cross-analysis results, a threshold range of the cross-domain threat index is set, and levels are divided according to different ranges of the index, and differentiated security strategies are formulated according to the level of the cross-domain threat index.

[0016] The beneficial effects of the present invention are as follows: by introducing a multi-level recognition mechanism of a primary security identification module and a deep learning detection module, it is possible to more accurately identify secure traffic, malicious traffic, and complex traffic data that is difficult to directly determine in network traffic; by integrating multi-source data information to form a comprehensive data stream, it is possible to accurately discover abnormal patterns and attack behaviors that are not obvious in a single data source, and improve the comprehensive network security protection capability; by using a graph neural network sub-module to perform graph structure modeling on the comprehensive data stream, it is possible to identify potential threat chains in network traffic data, and calculate their association strength, and form a threat chain association value based on abnormal tendency characters, and generate a threat chain association total value based on multiple threat chain association values ​​for identification, which can accurately evaluate the security of network traffic data and the hazards of threat chains. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 This is an overall architecture diagram of a network security comprehensive protection system based on deep learning according to the present invention;

[0018] Figure 2 This is a schematic diagram of the architecture of a deep learning detection module in a deep learning-based network security comprehensive protection system of the present invention. DETAILED DESCRIPTION

[0019] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.

[0020] In the description of this application, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of this application, "plurality" means two or more, unless otherwise clearly and specifically defined.

[0021] In the description of the present application, the term "for example" is used to mean "used as an example, illustration or description". Any embodiment described as "for example" in the present application is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is given to enable any technician in the field to implement and use the present invention. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art can recognize that the present invention can be implemented without using these specific details. In other examples, well-known structures and processes will not be elaborated in detail to avoid unnecessary details to obscure the description of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown, but is consistent with the widest scope consistent with the principles and features disclosed in the present application.

[0022] Example 1: Figure 1 As shown, a network security comprehensive protection system based on deep learning, the system includes:

[0023] The primary security identification module is used to perform security identification on network traffic data. The security identification module includes a primary identification submodule and a secondary identification submodule. The primary identification submodule is used to identify whether it is safe traffic, and the secondary identification submodule is used to identify whether it is malicious traffic.

[0024] Specifically, the primary security identification module is used to identify pre-stored security traffic information. First, the primary identification submodule is used to obtain the identity tag of the traffic initiator of the network traffic data, and then the database is quickly queried to see whether there is a whitelist tag corresponding to the identity tag. If so, the network traffic data can be quickly and accurately identified as security traffic. In this case, the network traffic data can be released; if the whitelist tag corresponding to the identity tag does not exist in the database, the matching identification result of whether the network traffic data is security traffic is unknown, and the network traffic data is uploaded to the secondary identification submodule to further determine whether the network traffic data is malicious traffic; the secondary identification submodule implements the identification decision of malicious traffic by analyzing the encryption features of the network traffic data. If the encryption feature A of the network traffic data matches the preset encryption feature A1 of the malicious traffic, a similarity threshold is pre-set (for example, set to 80%). If it is greater than the threshold, the network traffic data can be identified as malicious traffic, and interception can be performed on this basis. If the network traffic data is not identified as malicious traffic, it means that there is no object matching the encrypted feature A of the network traffic data in the preset encryption features of malicious traffic. However, it is still impossible to determine that the network traffic data is non-malicious traffic based on this and upload the network traffic data to the deep learning detection module.

[0025] A deep learning detection module is used to receive and identify network traffic data that cannot be determined by the primary security identification module; the deep learning detection module includes an abnormal character detection submodule, a multi-source data fusion submodule and a graph neural network submodule, the abnormal character detection submodule is used to identify characters with abnormal tendencies in network traffic data; the multi-source data fusion submodule is used to obtain auxiliary data sources and fuse them with network traffic to form a comprehensive data stream; the graph neural network submodule is used to receive the comprehensive data stream, construct graph structure data according to the comprehensive data stream, obtain the threat chain existing in the network traffic data, calculate the correlation strength of the threat chain, and generate the total value of the threat chain correlation.

[0026] Specifically, Figure 2As shown, the abnormal character detection submodule obtains service session character information in network traffic data, obtains abnormal tendency character distribution through a session character classification network, mines an abnormal tendency situation expression set based on the abnormal tendency characters, and the abnormal tendency situation expression set is a risky abnormal traffic state feature. Different abnormal characters are divided into risk intention levels, and the risk intention level division is to speculate the intention, and the intention is divided into multiple intention levels according to the position and frequency of the characters in the session; the multi-source data fusion submodule generates a comprehensive data stream by fusing the received abnormal tendency situation expression set and the auxiliary data source, and the auxiliary data source includes multi-source data such as log data, user behavior data, and threat intelligence data. The auxiliary data source and network traffic data are both data information in the same network domain, and the multi-source data fusion submodule is used to generate a comprehensive data stream through association analysis technology The graph neural network submodule is based on deep learning neural network technology, which takes IP addresses, domain names, etc. in network traffic data as graph nodes, and external data such as traffic transmission relationships and log access data as graph edges, models the graph structure, takes graph structure data and the fused comprehensive data stream as input data, learns the feature representation of nodes and edges through the graph attention network model, and calculates the association value for each potential threat chain in the graph (composed of a series of nodes and edges). The association value calculation method is based on the feature representation of nodes and edges, combined with the abnormal tendency expression set, and calculated through the aggregation function. The threat chain association value is used to measure the association strength between the threat chain composed of nodes and edges in the graph structure and the abnormal tendency in the network traffic data. A high association value indicates that the threat chain is very likely to be related to the current network attack activity. In the graph structure, a series of interconnected nodes and edges form a threat chain, which represents a potential attack path or malicious behavior sequence. Graph neural networks can discover these threat chains and evaluate their association strength and potential harm by aggregating and analyzing the feature representations of nodes and edges. The threat chain association value is calculated by considering multiple features of cross nodes and edges, such as interaction frequency, data traffic size, abnormal behavior patterns, etc. The threat chain association value is generated by the weighted average method. The association values ​​generated by each threat chain are integrated to form the total threat chain association value.

[0027] Specifically, the nodes in the graph represent entities (such as IP addresses, domain names, user IDs, etc.), and the edges represent the relationships between entities (such as traffic transmission, access records, social interactions, etc.). Initial features are assigned to the nodes and edges in the graph based on the raw data in the integrated data stream. The graph attention network model is used for training, and labeled training data is prepared. The training data contains the graph structure and corresponding labels (such as normal / abnormal, attack type, etc.) for supervised learning. The graph neural network model is trained using the training data. During the training process, the model learns how to predict the category of the node or evaluate the properties of the entire graph based on the feature representation of the node and edge. The trained graph neural network model is used to extract features from the new integrated data stream, and a feature representation vector is generated for each node in the graph. Based on the extracted node feature representation, the relationship between the nodes is further analyzed to discover potential threat chains. The threat chain is a series of interconnected nodes that represent potential attack paths or malicious behavior sequences. The correlation strength and potential harm of the threat chain are evaluated. The feature representation of the nodes and edges in the threat chain is aggregated and combined with threat intelligence data for comprehensive evaluation. The discovery results, correlation strength and potential hazards of the threat chain are output to the security confirmation and protection module, and corresponding security policies or response measures are formulated based on the output results and transmitted to the security confirmation and protection module at the same time.

[0028] The security confirmation protection module is used to determine whether the network traffic data is safe based on the total value of the threat chain association and generate an analysis report.

[0029] Specifically, analyze the structure of the threat chain and the total value of threat chain association, identify abnormal or unexpected patterns, combine external threat intelligence and known attack patterns, further verify the integrity and accuracy of the threat chain, and evaluate the abnormality of network traffic data based on the threat chain analysis results. If the association value of a threat chain is abnormally low, and some key nodes or edges on the chain are missing, it may indicate that the network traffic data is incomplete in this area. Combined with the location of the characters with abnormal tendencies in the network traffic data, a comprehensive analysis is performed to generate an analysis report. The report content includes but is not limited to: threat chain details, association values, potential hazards, recommended security strategies or response measures, and abnormal handling reports; if the association value of a threat chain is abnormally high, and the nodes and edges on the chain are highly matched with known attack patterns, the network traffic data is also judged to be unsafe. In the security confirmation and protection module, thresholds and judgment rules are set according to historical experimental data, and the threshold range is set. When the total value of the threat chain association exceeds the high threshold or is lower than the low threshold, it is used to trigger the exception handling process. When an anomaly is detected, the exception information is automatically recorded, including the type, time, source, etc. of the anomaly. According to the type of anomaly, corresponding response measures are executed, such as intercepting suspicious traffic, isolating infected devices, notifying security administrators, etc., and an exception handling report is generated, including information such as exception details, handling process, and handling results.

[0030] In this embodiment, an auxiliary data source is added to the network traffic data for synthesis, providing a more comprehensive network view, capable of capturing feature information of more dimensions, and by combining multiple types of data, it is easier to discover abnormal patterns or behaviors that are not obvious only in a single data source. The comprehensive data stream provides more contextual information for the graph neural network, which helps to identify hidden attacks or threats and solves the problem of reducing recognition accuracy by a single data source; the use of the graph neural network submodule can extract the feature representation of nodes from the graph structure data, which not only contains the attribute information of the node itself, but also incorporates the location of the node in the network, neighbor nodes and other information, and captures the complex interactive relationship between entities (such as IP addresses, domain names) in the network traffic data by considering the connection mode and strength between nodes, identifying potential threats and abnormal behaviors, identifying attack paths or malicious behavior sequences in the threat chain, accurately identifying abnormal behaviors and potential threats in network traffic, improving the accuracy of traffic security analysis, and thus improving the security of network protection.

[0031] Example 2: In the above example, multi-source data fusion is performed, and a graph neural network submodule is set to obtain the total value of threat chain association in combination with abnormal tendency characters to improve the accuracy of recognition and network protection security. This example makes further limitations on the above.

[0032] The deep learning detection module also includes a time series analysis submodule, which is used to receive a comprehensive data stream and establish a time series, generate a comprehensive data stream with time nodes, and classify the risk intentions of abnormal tendency characters in combination with the time nodes to generate a risk time set.

[0033] Specifically, first, it is necessary to unify the timestamp format in all data sources, mark each data record with an accurate timestamp, and add a time series integrity check step during the data fusion process. Check whether the timestamp is missing, repeated, or has outliers to ensure the continuity and accuracy of the time series. Fusion the data and time series features of multiple data sources, and store the results in a comprehensive data stream. At the same time, the comprehensive data stream is continuously updated according to the new time series data to maintain its timeliness and accuracy. Analyze the abnormal tendency characters in the comprehensive data stream, count each abnormal character and the time node where it appears, and generate a risk time set. The abnormal characters and time nodes in the risk time set correspond one to one and are sorted according to the time nodes.

[0034] The time series analysis submodule receives the threat chain association value, classifies the threat chain association value according to the time node to generate an association time set, combines the risk time set with the association time set, and selects the overlapping time nodes as heavy abnormal nodes.

[0035] Specifically, the graph neural network submodule receives a comprehensive data stream with time nodes, constructs graph structure data according to the comprehensive data stream, adds time attributes to each node and edge in the graph, calculates the correlation strength of the threat chain according to the time attributes and the nodes and edges, generates a threat chain correlation value, and transmits the generated threat chain correlation value to the timing analysis submodule. The timing analysis submodule receives the threat chain correlation value, classifies the threat chain correlation value according to the time nodes to generate an associated time set, combines the risk time set and the associated time set, filters out overlapping time nodes as heavy abnormal nodes, and filters out abnormal characters and threat chains based on the heavy abnormal nodes.

[0036] According to the data information of the heavy abnormal nodes, a sliding time window is set to perform in-depth re-inspection on the heavy abnormal nodes. The in-depth re-inspection is to define a time window with each heavy abnormal node as the center, and to perform in-depth re-inspection on the threat chain data and abnormal characters in the previous and next time windows. The threat chain association value is adjusted according to the result of the in-depth re-inspection, and the graph neural network submodule generates a total threat chain association value according to the adjusted threat chain association value.

[0037] Specifically, the heavy abnormal nodes refer to those specific time points that exhibit both abnormal character features and high threat chain association values ​​in the time series. These nodes are high-risk areas for potential threats in network traffic. By identifying and analyzing heavy abnormal nodes, the system can more accurately locate and respond to potential security threats, thereby effectively improving the efficiency and effectiveness of network protection. A time window is set to conduct in-depth review of the data information before and after the heavy abnormal nodes, and the threat chain association values ​​involved are adjusted according to the results of the in-depth review. The graph neural network submodule generates a total threat chain association value based on the adjusted threat chain association value.

[0038] Preferably, the size of the time window is initially set based on historical experimental data. In the specific analysis process, the sliding step size is set, which determines the frequency of window movement, that is, the time interval between two adjacent analyses. The setting of the sliding step size should be consistent with the shortest possible duration of historical abnormal behavior to ensure that important threat information is not missed. After the time window and sliding step size are initially set, they are dynamically adjusted through specific indicators such as recognition accuracy, false alarm rate, missed alarm rate, and response rate.

[0039] Centered on each major anomaly node, data windows are delineated within the time range before and after it according to the defined window size and step size. The start and end timestamps of the window should ensure full coverage of the anomaly node and be appropriately extended to include potential precursors or subsequent impacts. All data records within each window, including network traffic, log information, user behavior data, etc., are extracted from the comprehensive data stream for in-depth re-inspection.

[0040] According to the results of the deep re-inspection, the data changes in the previous and next time windows are analyzed, and the trend of changes in the threat chain correlation value of future time nodes is predicted with the current time node as the center, and the prediction results are transmitted to the graph neural network sub-module.

[0041] Specifically, historical data of threat chain association values ​​containing time series are extracted from the comprehensive data stream, and features used for prediction are extracted, such as historical threat chain association values, timestamps, abnormal character frequencies, etc. The ARIMA (autoregressive integrated moving average model) prediction model is selected, and the model is trained according to the results of deep verification. The model parameters are adjusted, and the trend of threat chain association value changes at future time nodes is predicted with the current time node as the center. The prediction results of threat chain association values ​​at future time points are output, and the prediction results are transmitted to the graph neural network sub-module, and transmitted together with the total threat chain association value to the security confirmation protection module to adjust the security strategy.

[0042] In this embodiment, a timing analysis submodule is added to generate a comprehensive data stream with time nodes. The generated threat chain association total value is adjusted according to the data changes in different time nodes or time periods (composed of time nodes and the time windows before and after), and the association value change trend of future time nodes is predicted based on the results of in-depth re-inspection, so as to further accurately identify whether the network traffic data is safe. At the same time, the threat chain association value change trend of the next time node is predicted based on the existing comprehensive data stream, thereby realizing the initiative and predictability of network security protection.

[0043] Example 3: In the above example, a timing analysis submodule is added to mark the time nodes of the comprehensive data flow, and at the same time, the heavy abnormal nodes are deeply re-inspected to predict the change trend of the threat chain correlation value at the next time node. However, when the heavy abnormal nodes are deeply re-inspected, it is found that the heavy abnormal nodes or threat chains span multiple network domains, and the overall associated attack behavior cannot be analyzed. Therefore, this example makes further improvements.

[0044] In the process of analyzing the data of heavy abnormal nodes and threat chains, cross-domain attacks may occur. In the existing technology, it is impossible to conduct a comprehensive analysis of the data of cross-domain attacks based on the correlation values ​​of heavy abnormal nodes and threat chains to obtain accurate identification results, resulting in reduced network protection security.

[0045] The deep learning detection module also includes a cross-domain analysis submodule, which is used to extract cross-domain data information based on heavy abnormal nodes and threat chains with cross-domain attacks, construct a cross-domain threat chain based on the cross-domain data analysis results, and generate a cross-domain threat index.

[0046] The cross-domain data analysis result is to identify similar cross-domain related attack behaviors, collect nodes and edges that frequently interact between different network domains, and generate a cross-domain threat chain based on cross nodes and edges; the cross-domain data analysis result is a comprehensive analysis based on the cross-domain data flow formed by cross-domain data and comprehensive data flow.

[0047] The cross-domain threat index is generated by combining a threat chain association value and a cross-domain threat chain association value, and the cross-domain threat chain association value is generated based on the cross-domain threat chain.

[0048] Specifically, in the above embodiment, when performing time series analysis, when identifying a major abnormal node or potential threat behavior, first check the source IP address, target IP address, domain name and other key information in the network traffic, log or user behavior data involved in these nodes or behaviors, and compare these key information with the predefined network domain boundary information to determine whether it crosses different network domains such as the internal network, external network, cloud service network, etc. If the key information appears in the data of multiple network domains at the same time, it is considered that there is a cross-domain situation.

[0049] When it is found that a major abnormal node or potential threat behavior may span multiple network domains, cross-domain data information is extracted from the major abnormal nodes and threat chains with cross-domain attacks, and the graph neural network submodule is used to conduct a comprehensive analysis of the cross-domain data. By identifying the similarity or correlation between nodes (such as IP addresses, domain names) and edges (such as traffic transmission relationships, access records) in different network domains, a cross-domain threat chain is constructed. According to the cross nodes and edges of the cross-domain threat chain, the cross-domain threat chain association value is calculated to identify similar cross-domain associated attack behaviors, especially nodes and edges that frequently interact between different network domains. The network domains include but are not limited to internal networks, external networks, and the like. The cross-domain data includes network traffic, logs, user behavior and other data collected from various network domains, and the cross-domain data and comprehensive data streams are comprehensively analyzed to form a cross-domain data stream. Similar cross-domain related attack behaviors are identified based on the cross-domain data stream. Specifically, a pattern matching algorithm is used to perform similarity analysis on traffic patterns, log records, user behaviors, etc. in the cross-domain data. Combined with historical attack cases, behavioral features similar to known cross-domain attack patterns are identified. Through association analysis technology, seemingly isolated but actually related attack behaviors in different network domains are connected in series to form a complete cross-domain attack chain. The calculated cross-domain threat chain association value is merged with the threat chain association value in a single network domain to form a cross-domain threat index. The threat chain association value in a single network domain and the cross-domain threat chain association value are calculated separately. The threat chain association value within a single network domain is calculated through the content of the above embodiment, while the cross-domain threat chain association value is generated based on the characteristics of the cross-nodes and edges of the cross-domain threat chain using the calculation method of the above embodiment. The threat chain association value within a single network domain and the cross-domain threat chain association value are fused using the weighted average method. During the fusion process, the weights are dynamically adjusted according to the importance of different network domains and the severity of cross-domain attacks. The fused result is the cross-domain threat index, which reflects the threat level of cross-domain attacks in network traffic. According to the specific value of the cross-domain threat index, a targeted security strategy is formulated. When the cross-domain threat index exceeds the preset threshold, the security response mechanism is automatically triggered, and the current network traffic data can be accurately judged as malicious traffic, and all attack processes and attack modes of malicious traffic can be accurately analyzed. At the same time, the threat chain of malicious traffic is analyzed according to the time series to obtain further predictions, and preventive security strategies and protective measures are generated.

[0050] The cross-domain threat index not only takes into account the threat situation within a single network domain, but also comprehensively considers the threat level of cross-domain attacks. The collaborative protection between different network domains enables internal networks, external networks, cloud service networks, etc. to share threat intelligence and protection experience, further improving the comprehensive network security protection function.

[0051] Embodiment 4: In the above embodiment, a cross-domain analysis submodule is set to conduct a comprehensive analysis on behaviors involving cross-domain attacks, and a cross-domain threat index is generated to judge the network security situation. This embodiment makes further improvements on the basis of the above embodiment.

[0052] Obtain the heavy abnormal nodes and deep re-inspection results of the heavy abnormal nodes with cross-domain attacks, obtain the periodic and trend characteristics of the time nodes, classify the cross-domain data according to the periodic and trend characteristics of the time nodes, perform cross-combination analysis on cross-domain data of different classifications, identify the similarity and correlation of abnormal characters between different network domains, and generate cross-analysis results.

[0053] Specifically, the periodicity and trend characteristics of time nodes are extracted from the heavy abnormal nodes and deep re-test results, and the time series analysis technology is used to identify the periodic patterns in the data. The linear regression method is used to identify the long-term or short-term trends in the time series data, and the key time node characteristics are extracted, such as the period length, trend slope, trend direction, etc. The classification standard is set according to the periodicity and trend characteristics of the time nodes, and is divided into the periodic explicit category, that is, the data shows a strong periodic pattern, such as the time nodes where the abnormal tendency characters appear are the daily or monthly peak and trough periods; the trend explicit category, that is, the data shows an obvious upward or downward trend over time, but does not show a periodic tendency; the abnormal prominent category, that is, the data has abnormal values ​​or mutation points that are significantly inconsistent with the overall trend, and irregular abnormal changes. According to the above classification standards, the cross-domain data is preliminarily screened and classified, and for each category, further refined analysis is performed, and the remaining two different category analysis methods are used to further refine the analysis and identify possible subcategories.

[0054] Cross-domain data of different classifications are cross-combined to form multiple combinations. For example, internal network data of the periodic explicit class is combined with external network data of the trend explicit class. The abnormal character distribution, traffic pattern, behavior characteristics, etc. in each combination are analyzed to find potential similarities or correlations. The graph neural network submodule is used to conduct in-depth analysis of the combined data to identify potential cross-domain threat chains and attack patterns.

[0055] Extract feature vectors of abnormal characters in different network domains, including frequency of occurrence, time distribution, associated behavior, etc., apply similarity calculation algorithms (such as cosine similarity, etc.) to calculate the similarity between abnormal characters in different network domains, and identify sets of abnormal characters with significant similar associations based on the similarity results. Combined with traffic patterns and behavioral feature information, generate cross-analysis results, including the composition of the cross-domain threat chain, attack paths, and potential impacts.

[0056] The correlation strength of different cross-domain threat chains is calculated based on the cross-analysis results, a threshold range of the cross-domain threat index is set, and levels are divided according to different ranges of the index. Differentiated security strategies are formulated based on the level of the cross-domain threat index.

[0057] Specifically, based on the cross-analysis results, a graph structure model of the cross-domain threat chain is constructed, and weights are assigned to each node and edge in the graph. Preferably, the weights are dynamically adjusted according to the similarity of abnormal characters, traffic size, and abnormal behavior degree factors, and the correlation strength of the cross-domain threat chain is calculated. The correlation strength can reflect the importance and potential harm degree of the threat chain. According to historical data and current security policies, the threshold range of the cross-domain threat index is preliminarily set. The effectiveness of the threshold is verified by actual operation data, and it is dynamically adjusted according to the feedback results. The cross-domain threat index is divided into different levels (such as low, medium, and high), and each level corresponds to a different threat level and response priority. According to the level of the cross-domain threat index, differentiated security policies are formulated for different threat situations. For cross-domain attacks with high threat levels, the emergency response mechanism is immediately activated, including traffic interception, system isolation, alarm notification, etc.; for cross-domain attacks with medium threat levels, a waiting observation time is set, monitoring and early warning are strengthened, and subsequent pattern changes of the attack are obtained during the waiting observation time to prepare for possible subsequent attacks; for cross-domain attacks with low threat levels, the attack mode and type are determined and the treatment method with the least impact is adopted to respond.

[0058] In this embodiment, by deeply rechecking the abnormal nodes, analyzing the periodic and trend characteristics of the time nodes, and cross-combination analysis of cross-domain data, the recognition accuracy of cross-domain threats is improved, and the problem of difficulty in accurately identifying complex threats across multiple network domains is solved; by constructing a graph structure model of the cross-domain threat chain and calculating its correlation strength, the importance and potential harm of cross-domain threats are effectively evaluated, and the problem of focusing on the correlation relationship within a single network domain and ignoring the cross-domain threat chain is solved; by setting the threshold range of the cross-domain threat index and dividing it into levels, a differentiated security strategy is formulated, so that the security response can be more accurate and efficient. By accurately identifying cross-domain threats, effectively classifying cross-domain data, and quantitatively evaluating the correlation strength of the cross-domain threat chain, the accuracy of cross-domain threat protection is significantly improved, the false alarm rate and missed alarm rate are reduced, and the stability of comprehensive network security protection is improved. The threshold range and level division of the cross-domain threat index are set, and security resources are reasonably allocated according to different levels to respond to the ever-changing network security threats.

[0059] It should be noted that in the above embodiments, the description of each embodiment has its own emphasis, and for parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0060] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0061] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0062] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0063] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0064] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0065] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A network security comprehensive protection system based on deep learning, characterized in that: The system includes: a primary security identification module, which is used to perform security identification on network traffic data, and the security identification module includes a primary identification submodule and a secondary identification submodule, wherein the primary identification submodule is used to identify whether it is security traffic, and the secondary identification submodule is used to identify whether it is malicious traffic; A deep learning detection module, used to receive and identify network traffic data that cannot be determined by the primary security identification module; the deep learning detection module includes an abnormal character detection submodule, a multi-source data fusion submodule and a graph neural network submodule; The abnormal character detection submodule obtains abnormal tendency character distribution through service session character information in network traffic data and a session character classification network, and obtains an abnormal tendency situation expression set according to the abnormal tendency characters; The multi-source data fusion submodule fuses the abnormal tendency situation expression set and the auxiliary data source to generate a comprehensive data stream; The graph neural network submodule is based on deep learning neural network technology, takes IP addresses and domain names in network traffic data as graph nodes, and takes external data as graph edges to model the graph structure; takes graph structure data and comprehensive data stream as input data, learns the feature representation of nodes and edges through the graph attention network model, and calculates the association value of each threat chain; and synthesizes all threat chain association values ​​to form a total threat chain association value; The security confirmation protection module is used to determine whether the network traffic data is safe based on the total value of the threat chain association and generate an analysis report; Among them, the abnormal tendency situation expression set is a set of abnormal traffic state features; the threat chain association value is used to measure the association strength between the threat chain composed of nodes and edges in the graph structure and the abnormal tendency in the network traffic data.

2. According to claim 1, a network security comprehensive protection system based on deep learning is characterized in that: The deep learning detection module also includes a time series analysis submodule, which is used to receive a comprehensive data stream and establish a time series, generate a comprehensive data stream with time nodes, and classify the risk intentions of abnormal tendency characters in combination with the time nodes to generate a risk time set.

3. A network security comprehensive protection system based on deep learning according to claim 2, characterized in that: The time series analysis submodule receives the threat chain association value, classifies the threat chain association value according to the time node to generate an associated time set, combines the risk time set with the associated time set, and selects the overlapping time nodes as heavy abnormal nodes.

4. A network security comprehensive protection system based on deep learning according to claim 3, characterized in that: According to the data information of the heavy abnormal nodes, a sliding time window is set to perform in-depth re-inspection on the heavy abnormal nodes. The in-depth re-inspection is to define a time window with each heavy abnormal node as the center, and to perform in-depth re-inspection on the threat chain data and abnormal characters in the previous and next time windows. The threat chain association value is adjusted according to the result of the in-depth re-inspection, and the graph neural network submodule generates a total threat chain association value according to the adjusted threat chain association value.

5. A network security comprehensive protection system based on deep learning according to claim 4, characterized in that: According to the results of the deep re-inspection, the data changes in the previous and next time windows are analyzed, and the trend of changes in the threat chain correlation value of future time nodes is predicted with the current time node as the center, and the prediction results are transmitted to the graph neural network sub-module.

6. A network security comprehensive protection system based on deep learning according to claim 4, characterized in that: The deep learning detection module also includes a cross-domain analysis submodule, which is used to extract cross-domain data information based on heavy abnormal nodes and threat chains with cross-domain attacks, construct a cross-domain threat chain based on the cross-domain data analysis results, and generate a cross-domain threat index.

7. A network security integrated protection system based on deep learning according to claim 6, characterized in that: The cross-domain data analysis result is to identify similar cross-domain related attack behaviors, collect nodes and edges that frequently interact between different network domains, and generate a cross-domain threat chain based on cross nodes and edges; the cross-domain data analysis result is a comprehensive analysis based on the cross-domain data flow formed by cross-domain data and comprehensive data flow.

8. A network security integrated protection system based on deep learning according to claim 6, characterized in that: The cross-domain threat index is generated by combining a threat chain association value and a cross-domain threat chain association value, and the cross-domain threat chain association value is generated based on the cross-domain threat chain.

9. A network security integrated protection system based on deep learning according to claim 6, characterized in that: Obtain the heavy abnormal nodes and deep re-inspection results of the heavy abnormal nodes with cross-domain attacks, obtain the periodic and trend characteristics of the time nodes, classify the cross-domain data according to the periodic and trend characteristics of the time nodes, perform cross-combination analysis on cross-domain data of different classifications, identify the similarity and correlation of abnormal characters between different network domains, and generate cross-analysis results.

10. A network security integrated protection system based on deep learning according to claim 9, characterized in that: The correlation strength of different cross-domain threat chains is calculated based on the cross-analysis results, a threshold range of the cross-domain threat index is set, and levels are divided according to different ranges of the index. Differentiated security strategies are formulated based on the level of the cross-domain threat index.

Citation Information

Patent Citations

  • Graph neural network construction method and abnormal flow detection method based on graph neural network

    CN112383516A

  • Malicious traffic detection method based on integral space-time diagram convolutional neural network fused with space-time attention

    CN117579290A