Active noise reduction based traffic data processing method and system

By calculating the maximum number of network attacks and their half-life, a comprehensive traffic data impact factor is constructed, and active noise reduction processing is performed. This solves the problems of high false alarm rates and performance impact of network security devices, and achieves a reduction in the number of alarms and an increase in the accuracy of threat identification.

CN118890199BActive Publication Date: 2025-11-04SHANXI CHINA MOBILE COMM CORP +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411098853.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-12
Publication Date
2025-11-04
Estimated Expiration
2044-08-12

AI Technical Summary

Technical Problem

Existing network security equipment alarm systems have a high false alarm rate, causing network administrators to overlook real threats, and existing real-time traffic analysis methods have a negative impact on network performance.

Method used

By acquiring alarm information data from network security devices, calculating the maximum number of network attacks and the attack half-life, constructing a comprehensive traffic data impact, and performing proactive noise reduction processing, including blocking traffic data, randomly blocking and allowing it, to reduce the number of alarms.

Benefits of technology

It reduced the number of alarms from network security devices, accurately identified real threat behaviors, reduced the impact on network performance, and achieved efficient traffic data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118890199B_ABST
    Figure CN118890199B_ABST
Patent Text Reader

Abstract

The application provides a flow data processing method and system based on active noise reduction, which comprises the following steps: obtaining alarm information data generated by a network security device at a current time; determining the maximum attack number of each network attack type corresponding to network attack and the attack half-life period of each network attack type corresponding to network attack of the network security device within a preset period according to the alarm information data, and calculating the comprehensive flow data influence degree of the network security device at the current time according to the maximum attack number and the attack half-life period of all network attack types; and performing corresponding active noise reduction processing on the flow data of the network security device when the comprehensive flow data influence degree is greater than a preset influence degree threshold. The application reduces the alarm amount of the network security device and accurately identifies the real threat behavior of the current security device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a traffic data processing method and system based on active noise reduction. Background Technology

[0002] In today's digital environment, cybersecurity is of paramount importance. Firewalls, Intrusion Detection Systems (IDS), and Intrusion Prevention Systems (IPS), among other cybersecurity devices, are widely used to monitor and protect networks from various threats. These security devices often generate a large number of alerts, including many false alarms.

[0003] Existing technologies, such as rule-based detection and signature-based detection, often produce high false alarm rates, which may cause network administrators to overlook real threats and result in actual network intrusions being overwhelmed by a large number of false alarms.

[0004] Therefore, there is an urgent need for a traffic data processing method and system based on active noise reduction to solve the above problems. Summary of the Invention

[0005] To address the problems existing in the prior art, the present invention provides a traffic data processing method and system based on active noise reduction.

[0006] This invention provides a traffic data processing method based on active noise reduction, comprising:

[0007] Obtain alarm information data generated by network security devices at the current moment;

[0008] Based on the alarm information data, determine the maximum number of network attacks corresponding to each type of network attack that the network security device receives within a preset period, as well as the attack half-life of each type of network attack. Based on the maximum number of network attacks and the attack half-life of all network attack types, calculate the comprehensive traffic data impact of the network security device at the current moment.

[0009] If the impact of the comprehensive traffic data is determined to be greater than a preset impact threshold, the traffic data of the network security device is subjected to corresponding active noise reduction processing.

[0010] The maximum number of attacks is obtained based on the number of attacks received by the network security device at various historical moments within a preset period; the attack half-life represents the time required for the number of attacks to reach half of the corresponding maximum number of attacks when the network security device is attacked within a preset period.

[0011] According to the present invention, a traffic data processing method based on active noise reduction is provided, the method further includes:

[0012] Obtain the cumulative number of times the network security device has been attacked by each type of network attack at each historical moment within a preset period;

[0013] Based on a quadratic function, and according to the cumulative number of attacks at each historical moment, the attack cycle function of each type of network attack is fitted to obtain the attack cycle function of each type of network attack.

[0014] Based on the attack cycle function, the maximum and minimum cumulative number of attacks for each type of network attack within a preset period are determined, and the maximum cumulative number of attacks is taken as the maximum number of attacks for the corresponding type of network attack.

[0015] The standard attack value for each type of network attack is calculated based on the difference between the maximum cumulative number of attacks and the minimum cumulative number of attacks.

[0016] Based on the attack cycle function and the attack quantity standard value, the attack half-life of each type of network attack is calculated, and the attack half-life parameter function is constructed based on the attack half-life and the maximum number of attacks.

[0017] According to a traffic data processing method based on active noise reduction provided by the present invention, the step of calculating the comprehensive traffic data impact of the network security device at the current moment based on the maximum number of attacks and the attack half-life of all types of network attacks includes:

[0018] Based on the comprehensive traffic data impact formula, the comprehensive traffic data impact of the network security device at the current moment is calculated according to the maximum number of attacks and the attack half-life of all network attack types. The comprehensive traffic data impact formula is as follows:

[0019]

[0020] in, Indicates the overall impact of traffic data. Indicates the current moment. Indicates the first i The maximum number of attacks corresponding to a network attack type. Indicates the first i The attack half-life corresponding to the type of network attack is as follows: CThis indicates that the network security device includes [the following] within the current preset period. C Network attacks of various types.

[0021] According to a traffic data processing method based on active noise reduction provided by the present invention, the step of performing corresponding active noise reduction processing on the traffic data of the network security device when the overall traffic data influence is determined to be greater than a preset influence threshold includes:

[0022] If the influence of the comprehensive traffic data is determined to be greater than a preset influence threshold, it is determined whether the difference between the influence of the comprehensive traffic data and the preset influence threshold is less than a preset influence difference. If the influence difference is greater than or equal to the preset influence difference, a traffic data blocking operation is performed on the network security device.

[0023] If the impact difference is less than the preset impact difference, a random blocking operation is performed on the traffic data generated by the corresponding attack source in the network security device, wherein the attack source includes the address information of the sending end of the network attack;

[0024] The method further includes:

[0025] If the overall traffic data impact is determined to be less than or equal to the preset impact threshold, a traffic data passage operation is performed on the network security device.

[0026] According to the present invention, a traffic data processing method based on active noise reduction is provided, wherein if the impact difference is less than the preset impact difference, a random traffic data blocking operation is performed on the traffic data generated by the target attack source in the network security device, comprising:

[0027] If the impact difference is determined to be less than the preset impact difference, the number of historical attacks by the attack source attacking the network security device in the previous preset period is obtained.

[0028] Based on the historical attack count, the attack half-life parameter function, and the maximum attack count, the attack cycle parameter of the attack source within the current preset cycle is calculated.

[0029] If the attack cycle parameter is determined to be less than or equal to a preset attack cycle threshold, the blocking probability is calculated based on the difference between the attack cycle parameter and the preset attack cycle threshold, wherein the preset attack cycle threshold is half the duration corresponding to the preset cycle.

[0030] Based on the traffic data generated by the attack source, a random number is generated corresponding to each traffic data, and traffic data whose random number is less than the blocking probability is blocked.

[0031] According to a traffic data processing method based on active noise reduction provided by the present invention, the step of acquiring alarm information data generated by network security devices at the current moment includes:

[0032] Based on the network attacks launched by different attack sources against the network security device at the current moment, obtain the network attack type information, attack source address information, attack time point information within the current preset period, and attack count information corresponding to the attack time point information.

[0033] The alarm information data is obtained based on the network attack type information, the attack source address information, the attack time point information, and the attack count information.

[0034] The present invention also provides a traffic data processing system based on active noise reduction, comprising:

[0035] The converter module is used to acquire alarm information data generated by network security devices at the current moment;

[0036] The analyzer module is used to determine, based on the alarm information data, the maximum number of network attacks corresponding to each type of network attack that the network security device receives within a preset period, as well as the attack half-life of each type of network attack, and to calculate the comprehensive traffic data impact of the network security device at the current moment based on the maximum number of network attacks and the attack half-life of all network attack types.

[0037] The noise reduction module is used to perform corresponding active noise reduction processing on the traffic data of the network security device when it is determined that the influence of the comprehensive traffic data is greater than a preset influence threshold.

[0038] The maximum number of attacks is obtained based on the number of attacks received by the network security device at various historical moments within a preset period; the attack half-life represents the time required for the number of attacks to reach half of the corresponding maximum number of attacks when the network security device is attacked within a preset period.

[0039] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the traffic data processing method based on active noise reduction as described above.

[0040] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the traffic data processing method based on active noise reduction as described above.

[0041] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the traffic data processing method based on active noise reduction as described above.

[0042] The present invention provides a traffic data processing method and system based on active noise reduction. By calculating the maximum number of network attacks and the attack half-life of all types of network attacks received by the network security device within a preset period, the comprehensive traffic data impact of the network security device at the current moment is obtained. Then, when it is determined that the comprehensive traffic data impact is greater than the preset impact threshold, the traffic data of the network security device is subjected to corresponding active noise reduction processing, thereby reducing the alarm volume of the network security device and accurately identifying the actual threat behavior of the current security device. Attached Figure Description

[0043] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0044] Figure 1 This is a flowchart illustrating the traffic data processing method based on active noise reduction provided by the present invention.

[0045] Figure 2 A graph corresponding to the attack half-life parameter function provided by this invention;

[0046] Figure 3 A schematic diagram of the traffic data processing system based on active noise reduction provided by the present invention;

[0047] Figure 4 This is an overall architecture diagram of the traffic data processing system based on active noise reduction provided by the present invention;

[0048] Figure 5 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0049] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0050] Existing optimization techniques for network security device alarms primarily focus on improving detection results. However, a problem exists: regardless of whether new models are created, optimized, or real-time analysis tools and intelligent management tools are added, they haven't significantly altered the original device alarm data. In fact, adding new devices or analysis tools may increase alarm data and the probability of duplicate alarms, further increasing subsequent analysis tasks. For example, in existing technologies, machine learning algorithms are used to optimize alarm concentrators. While machine learning methods process alarms, they don't change the original alarm volume of network security devices. Especially when new alarms are added to the alarm concentrator, alarm analysis requires checking not only the alarms in the concentrator but also the alarms of the original network devices, leading to increased workload and false alarm rate.

[0051] Meanwhile, existing real-time traffic analysis and deep inspection methods may negatively impact network performance and introduce latency, posing a challenge for applications that require high performance and low latency.

[0052] To address the problems of existing technologies, this invention aims to reduce the number of device alarms. It actively denoises existing alarm data based on multi-party security computation, processing traffic data without generating new alarms. This invention achieves two main technological breakthroughs: First, it assesses the threat level of the current security device by combining attack half-life, and then, based on the assessment result, blocks traffic through the active denoising process, further reducing the number of alarms. Second, the active denoising process only requires simple comparison and judgment, without training operations, and has no significant impact on network performance. It should be noted that the traffic data processing method based on active denoising provided by this invention can be applied to various network security scenarios, such as the Internet of Things and cloud security services; this invention does not specifically limit the application scenarios.

[0053] Figure 1 This is a flowchart illustrating the traffic data processing method based on active noise reduction provided by the present invention, as shown below. Figure 1 As shown, the present invention provides a traffic data processing method based on active noise reduction, comprising:

[0054] Step 101: Obtain alarm information data generated by network security devices at the current moment.

[0055] In this invention, each network security device generates an alarm log, which mainly includes: alarm name, source address, destination address, start time, end time, and alarm count. Based on the information in these alarm logs, this invention collects the necessary data, processes this data according to the corresponding data format, and obtains the alarm information data generated by the network security device at the current moment.

[0056] Based on the above embodiments, obtaining the alarm information data generated by the network security device at the current moment includes:

[0057] Based on the network attacks launched by different attack sources against the network security device at the current moment, obtain the network attack type information, attack source address information, attack time point information within the current preset period, and attack count information corresponding to the attack time point information.

[0058] The alarm information data is obtained based on the network attack type information, the attack source address information, the attack time point information, and the attack count information.

[0059] Specifically, in this invention, the alarm information data mainly includes network attack type information, attack source address information, attack time point information, and attack count information. Among them, the network attack type information includes, but is not limited to, DDoS (Distributed Denial of Service) attacks, SQL injection, cross-site scripting (XSS), malware propagation, port scanning, etc.

[0060] Attack source address information is key to locating the source of an attack, including IP address, domain name (if available), and possible geographical location information.

[0061] Attack time point information refers to the exact time or time range when an attack occurs. In this invention, this information mainly represents the time information corresponding to when a network security device is attacked within a preset period. For example, when the preset period is 60 units of time, one attack time point information is that the network attack occurs in the 5th unit of time.

[0062] Attack count information refers to the number of attack attempts of the same type or from the same source address within a preset period.

[0063] Step 102: Based on the alarm information data, determine the maximum number of network attacks corresponding to each type of network attack that the network security device receives within a preset period, as well as the attack half-life of each type of network attack. Based on the maximum number of network attacks and the attack half-life of all network attack types, calculate the comprehensive traffic data impact of the network security device at the current moment.

[0064] In this invention, the cycle of network attack behavior is analyzed, and the attack half-life is used as an important parameter to process traffic data.

[0065] Half-life (symbol t½) is the time required for the quantity of (matter) to decrease to half its initial value. This term is commonly used in nuclear physics to describe the rate at which unstable atoms undergo radioactive decay or the survival time of stable atoms. In this invention, the attack half-life parameter function is provided as follows:

[0066] ;

[0067] in, y This indicates the current level of impact (e.g., when the maximum number of attacks within a preset period is 200, it corresponds to the maximum level of impact; when the impact of the attack on the system decreases to half of the maximum level of impact, the current level of impact is 100). Max This refers to the maximum number of attacks. T It is the attack half-life. t This is the current time (e.g., the 4th unit of time if the preset period is 60 units of time). The formula means that time has elapsed within a preset period. T At that time, the impact of a certain type of attack on the system is reduced to half of its original value.

[0068] In this invention, the attack half-life is related to two characteristics of the attack behavior: attack intensity and duration. When calculating the attack half-life, historical data is used to analyze the number of attacks per unit time corresponding to the attack source IP, thereby obtaining the maximum number of attacks for each attack type. The corresponding attack half-life is then calculated using the aforementioned attack half-life parameter function.

[0069] Step 103: If the influence of the comprehensive traffic data is determined to be greater than the preset influence threshold, perform corresponding active noise reduction processing on the traffic data of the network security device.

[0070] The maximum number of attacks is obtained based on the number of attacks received by the network security device at various historical moments within a preset period; the attack half-life represents the time required for the number of attacks to reach half of the corresponding maximum number of attacks when the network security device is attacked within a preset period.

[0071] In this invention, when the impact of traffic data is determined to be greater than a preset threshold, active noise reduction measures will be taken to intervene in or process traffic data that may have a negative impact, thereby reducing its potential risks or effects. In this invention, the active noise reduction is mainly implemented through blocking methods. For example, when the threat level is low, all traffic is allowed; when the threat level is medium, traffic is allowed randomly; and when the threat level is high, traffic is not allowed.

[0072] The traffic data processing method based on active noise reduction provided by this invention calculates the comprehensive traffic data impact of a network security device at the current moment by using the maximum number of attacks and the attack half-life of all network attack types received by the network security device within a preset period. Then, when it is determined that the comprehensive traffic data impact is greater than a preset impact threshold, the traffic data of the network security device is subjected to corresponding active noise reduction processing, thereby reducing the alarm volume of the network security device and accurately identifying the actual threat behavior of the current security device.

[0073] Based on the above embodiments, the method further includes:

[0074] Obtain the cumulative number of times the network security device has been attacked by each type of network attack at each historical moment within a preset period;

[0075] Based on a quadratic function, and according to the cumulative number of attacks at each historical moment, the attack cycle function of each type of network attack is fitted to obtain the attack cycle function of each type of network attack.

[0076] Based on the attack cycle function, the maximum and minimum cumulative number of attacks for each type of network attack within a preset period are determined, and the maximum cumulative number of attacks is taken as the maximum number of attacks for the corresponding type of network attack.

[0077] The standard attack value for each type of network attack is calculated based on the difference between the maximum cumulative number of attacks and the minimum cumulative number of attacks.

[0078] Based on the attack cycle function and the attack quantity standard value, the attack half-life of each type of network attack is calculated, and the attack half-life parameter function is constructed based on the attack half-life and the maximum number of attacks.

[0079] Every network security device generates alarm logs, which mainly include alarm name, source address, destination address, start time, end time, and alarm count. In this invention, based on the data required to calculate the attack half-life, these alarm logs are first converted to obtain the data format shown in Table 1:

[0080] Table 1 Alarm Data Conversion Results

[0081]

[0082] In this invention, timing is achieved through a broadcast clock, for example, with a default frequency of one minute, meaning a broadcast occurs once every minute, to synchronously collect half-life calculation data within each preset period. The specific steps are as follows:

[0083] During the initialization phase, the initial time is set to t0. In this invention, the broadcast clock parameter t is set as the unit time, with a default value of 1 minute. t0 elapses for time t until time t1 arrives. An attack cycle is defined as 60 unit times, i.e., one attack cycle is 1 hour, thus the attack half-life is calculated within one attack cycle.

[0084] Furthermore, every unit of time, a signal sent by the broadcast clock is acquired, and based on each unit of time, the attack information corresponding to the network security device (as shown in the data structure in Table 1) is summarized.

[0085] Furthermore, after one attack cycle, such as 60 minutes, the existing attack information is processed and analyzed to calculate the number of attacks for each attack type. For example, the nmap scan attack types can be summarized as shown in Table 2:

[0086] Table 2 Summary of Attack Data

[0087]

[0088] In Table 2, each data entry represents a required output data format. For example, Converter 01 may have identified multiple attacks, namely nmap scan attacks targeting 192.168.0.22 and 192.168.0.23, with 86 and 56 attacks respectively.

[0089] Next, the attack cycle is calculated based on the attack type, source IP, time point, and number of attacks. For example, the attack source IP 192.168.0.22 has 86 attack behaviors on Converter 01 at time point t1; and 77 attack behaviors on Converter 02 at time point t5; and so on. 10 At any given time, the total number of attacks is 60. Similarly, the number of attacks from the attacking source IP at all points in time within a preset period can be obtained, and the summary results are shown in Table 3.

[0090] Table 3 Summary of Attack Counts from a Certain Attack Source IP

[0091]

[0092] In this invention, the time point is considered as the x-coordinate, and the cumulative value of the number of attacks is considered as the y-coordinate, and a quadratic function is used for fitting. According to Table 3 above, the relevant coordinates can be obtained:

[0093] The cumulative attack count at time point t1 is 86, and the coordinates are (1, 86).

[0094] The cumulative number of attacks at time point t5 is 86 + 77 = 163, with coordinates (5, 163).

[0095] Time point t 10 The cumulative number of attacks corresponds to 163 + 60 = 223, with coordinates (10, 223).

[0096] Time point t 18 The cumulative number of attacks corresponds to 223 + 93 = 316, with coordinates (18, 316).

[0097] Using the quadratic function y=ax 2 Fitting the above coordinates with +bx+c, we get:

[0098] a = -0.2690456135602434;

[0099] b=18.409440420189956;

[0100] c = 70.78738795391274;

[0101] The final attack cycle function for this type of network attack is:

[0102] y = -0.27x 2 +18.41x+70.79.

[0103] Accordingly, through the above calculation process, the attack cycle functions for various types of attacks targeting IP address 192.168.0.22 can be obtained. For example, nmap scan: y=a1x 2 +b1x+c1; Brute force solution: y=a2x 2 +b2x+c2; SQL injection: y=a3x 2 Fitting results for attack types such as +b3x and +c3. It should be noted that for any given attack source IP, that IP may not be involved in all types of attacks; only the attack types included by that IP are counted.

[0104] Finally, calculate the time corresponding to the standard attack value in each attack cycle function. For example, for a nmap scan, its attack cycle function is y = -0.27x. 2+18.41x + 70.79. Since the function is fitted to the number of attacks using an additive approach, it is an increasing function. Therefore, within the attack period, y = -0.27x 2 The minimum value of +18.41x+70.79 appears at x=0, and the maximum value appears at x=60. We then calculate the values ​​corresponding to these two points and subtract the minimum value from the maximum value to obtain the difference in the number of attacks. That is, when x=0, the minimum value of y is 70.79; when x=60, the maximum value of y is 203.39. Therefore, the standard attack value is (203.39-70.79) / 2+70.79=137.09.

[0105] Then, based on the attack periodic function and considering that the value of x should be within the domain, when y = 137.09, the corresponding value of x is 3.81. Therefore, when x = 3.81, the standard value of the attack quantity is obtained, and the attack half-life T is approximately 3.81 ≈ 4.

[0106] In one embodiment, assuming a maximum attack count of 203.39 ≈ 203, the impact of the attack on the system should be calculated as follows: Within the current attack cycle, model and analyze the attack behavior against a specific IP address, combining the maximum impact with the attack half-life to determine the degree of impact on the system. If the attack half-life is 4, then at time 4, the attack count should decrease to half of the maximum attack count of 203 within 60 cycles, and the impact of the network attack on the system should also decrease to half of the maximum impact. For example, for the aforementioned attack source IP 192.168.0.22, the attack half-life parameter function corresponding to the impact of the nmap attack type is:

[0107] .

[0108] As time progresses, the impact of nmap attacks on the system decreases. Based on the attack half-life calculation process described above, the attack half-life corresponding to each type of network attack is obtained, as shown in Table 4.

[0109] Table 4 Attack Half-Life

[0110]

[0111] Based on the above embodiments, the step of calculating the comprehensive traffic data impact of the network security device at the current moment according to the maximum number of attacks and the attack half-life of all network attack types includes:

[0112] Based on the comprehensive traffic data impact formula, the comprehensive traffic data impact of the network security device at the current moment is calculated according to the maximum number of attacks and the attack half-life of all network attack types. The comprehensive traffic data impact formula is as follows:

[0113]

[0114] in, Indicates the overall impact of traffic data. Indicates the current moment. Indicates the first i The maximum number of attacks corresponding to a network attack type. Indicates the first i The attack half-life corresponding to the type of network attack is as follows: C This indicates that the network security device includes [the following] within the current preset period. C Network attacks of various types.

[0115] In this invention, the alarm logs generated by the network security device are constructed in the following specific data format: Table 5.

[0116] Table 5 Data Transmission of Network Security Devices

[0117]

[0118] The data in Table 5 above allows us to statistically determine the maximum number of attacks a particular network security device can suffer from a specific type of network attack within a preset period. Furthermore, assuming the current time is... The impact of the current time's comprehensive traffic data Influence now (abbreviation) IF now The calculation method is as follows:

[0119]

[0120] In this invention, This represents the attack half-life of a certain type of network attack, assuming that a total of [number] attacks are identified within the current attack cycle. C This type of attack, by all C The effects of these attacks are cumulative (i.e., from...) i =1 to C ). Indicates the number within the current network security device i The maximum number of attacks of a particular network attack type within a single period (default is 60 time units, or 1 hour). This is then used to calculate the overall impact of the traffic data. It determines the current network security status of the network security device and handles the traffic processed by the security device based on the network security status.

[0121] This invention comprehensively assesses the impact of all network attack types, thereby enabling unified operations across all attack types based on this assessment. Specifically, it calculates the impact of each network attack type and then sums the impact results to obtain the current overall traffic data impact level. Based on this impact value, the threat status currently faced by network security devices is determined, and the overall impact of traffic data is determined by setting a threshold. The levels of high, middle, and low education.

[0122] Based on the above embodiments, the step of performing corresponding active noise reduction processing on the traffic data of the network security device when it is determined that the overall traffic data influence is greater than a preset influence threshold includes:

[0123] If the influence of the comprehensive traffic data is determined to be greater than a preset influence threshold, it is determined whether the difference between the influence of the comprehensive traffic data and the preset influence threshold is less than a preset influence difference. If the influence difference is greater than or equal to the preset influence difference, a traffic data blocking operation is performed on the network security device.

[0124] If the impact difference is less than the preset impact difference, a random blocking operation is performed on the traffic data generated by the corresponding attack source in the network security device, wherein the attack source includes the address information of the sending end of the network attack;

[0125] The method further includes:

[0126] If the overall traffic data impact is determined to be less than or equal to the preset impact threshold, a traffic data passage operation is performed on the network security device.

[0127] In this invention, the preset impact threshold can be set to 50% of the historical maximum number of attacks by default. If this threshold is exceeded, noise reduction is performed. Preferably, in one embodiment, after running for a period of time, the threshold can be updated based on the impact of the comprehensive traffic data each time (e.g., adjusted based on the ratio of the impact of the comprehensive traffic data between two preset periods).

[0128] In this invention, the active noise reduction process filters network device traffic. The active noise reduction strategy can be as follows: when the threat level is low, if the overall traffic data impact is less than or equal to a preset impact threshold, all traffic is allowed; when the threat level is medium, if the overall traffic data impact is greater than the preset impact threshold, and the difference between two traffic sources is less than the preset impact difference, traffic is allowed randomly; when the threat level is high, if the overall traffic data impact is greater than the preset impact threshold, and the difference between two traffic sources is greater than the preset impact difference, traffic is not allowed. In this invention, the overall traffic data impact obtained based on the attack half-life represents the threat level change result under ideal and general conditions, which can be used as a benchmark to judge the attack behavior suffered by the current security device A, thereby randomly blocking the traffic of a certain attack source IP.

[0129] Based on the above embodiments, the step of performing random traffic data blocking operation on the traffic data generated by the target attack source in the network security device if the impact difference is less than the preset impact difference includes:

[0130] If the impact difference is determined to be less than the preset impact difference, the number of historical attacks by the attack source attacking the network security device in the previous preset period is obtained.

[0131] Based on the historical attack count, the attack half-life parameter function, and the maximum attack count, the attack cycle parameter of the attack source within the current preset cycle is calculated.

[0132] If the attack cycle parameter is determined to be less than or equal to a preset attack cycle threshold, the blocking probability is calculated based on the difference between the attack cycle parameter and the preset attack cycle threshold, wherein the preset attack cycle threshold is half the duration corresponding to the preset cycle.

[0133] Based on the traffic data generated by the attack source, a random number is generated corresponding to each traffic data, and traffic data whose random number is less than the blocking probability is blocked.

[0134] Current methods for handling attack source IPs only offer two states: "block" and "allow". This invention proposes a random filtering approach, which optimizes the two existing methods by dynamically adjusting the request traffic of a particular attack source IP based on its threat level.

[0135] Specifically, in one embodiment, using the current time as a baseline, the number of nmap scan attacks on IP: 192.168.0.22 in the previous attack cycle (default 60 units of time) is first calculated to determine the attack status of this IP in the nmap scan process. Assuming the calculated historical attack count in the previous attack cycle is 500, and the number of attacks received in the current attack cycle is 203, these are substituted into the corresponding attack half-life parameter function:

[0136] ;

[0137] Obtain the value x1 of the corresponding attack cycle parameter. Figure 2 For a graph showing the attack half-life parameter function provided by this invention, please refer to [the relevant source]. Figure 2 As shown.

[0138] Furthermore, in this invention, based on the analysis of the obtained attack cycle parameters, the following two situations exist: the first situation is that the attack cycle parameter x1 is in Figure 2 If the value of x=30 (based on half a cycle; the current attack cycle is 60, so half is 30) is to the left of this value, it indicates a high threat risk and requires blocking.

[0139] Another scenario is when the attack cycle parameter x1 is in Figure 2 The right side of x=30 in ( Figure 2 (Not shown in the image) This indicates that the attack is in its final stages or has not yet posed a substantial threat, and it is not necessary to block it at this time.

[0140] Furthermore, in this invention, when the time point corresponding to the attack cycle parameter x1 has not yet reached half of the current cycle, the specific blocking process is related to the distance from half of the attack cycle; the greater the distance, the higher the blocking rate. Taking a preset cycle of 60 as an example, the blocking probability P is calculated as follows:

[0141] ;

[0142] If x1=8, then P=0.22=22%.

[0143] Furthermore, the blocking process in this invention involves discarding each traffic stream based on a generated random number. A random number (0, 1) is generated for each request traffic stream, and the magnitude of the random number corresponding to each traffic stream is compared to the blocking probability P. If the random number is less than P, the traffic stream is blocked; if it is greater than P, the traffic stream passes normally. Through this blocking process, the more attacks 192.168.0.22 accumulates within a unit of time, the smaller the corresponding value of x becomes, and the further it is from half of the preset period, resulting in a higher blocking probability. For example, in the above embodiment, the maximum blocking rate is 30%.

[0144] This invention protects network security devices by blocking traffic from the source IP of abnormal attacks, fundamentally reducing the number of alarms for a network security device and achieving the effect of active noise reduction.

[0145] The active noise reduction-based traffic data processing system provided by the present invention will be described below. The active noise reduction-based traffic data processing system described below can be referred to in correspondence with the active noise reduction-based traffic data processing method described above.

[0146] Figure 3 This is a schematic diagram of the traffic data processing system based on active noise reduction provided by the present invention, as shown below. Figure 3 As shown, this invention provides a traffic data processing system based on active noise reduction, including a converter module 301, an analyzer module 302, and a noise reduction module 303. The converter module 301 is used to acquire alarm information data generated by a network security device at the current moment. The analyzer module 302 is used to determine, based on the alarm information data, the maximum number of network attacks corresponding to each type of network attack received by the network security device within a preset period, and the attack half-life corresponding to each type of network attack. Based on the maximum number of network attacks and the attack half-life for all network attack types, it calculates the comprehensive traffic data impact of the network security device at the current moment. The noise reduction module 303 is used to perform corresponding active noise reduction processing on the traffic data of the network security device when the comprehensive traffic data impact is determined to be greater than a preset impact threshold. The maximum number of attacks is obtained based on the number of attacks received by the network security device at various historical moments within a preset period. The attack half-life represents the time required for the number of attacks to reach half of the corresponding maximum number of attacks when the network security device is attacked within a preset period.

[0147] In this invention, the input of the noise reduction module is connected to the output of devices such as routers and switches, and the output of the noise reduction module is connected to the input of network security devices (such as IDS, WAF, and IPS). The main function of the noise reduction module is to perform network traffic filtering tasks. Based on the comprehensive traffic data impact obtained by the analyzer module, it generates corresponding dynamic condition parameters, establishes different filtering models, and achieves active noise reduction of attack traffic.

[0148] The converter module's input is connected to the output of the network security device to collect and process data (alarm logs) intercepted by the network security device. This data records information such as the attack source IP, destination IP, suspected attack type, and attack time. The converter module's main function is to convert the format of this data before inputting it into the analyzer module for analysis and processing.

[0149] The analyzer module's input is connected to the converter module's output and then to the noise reduction module. The analyzer module transmits the calculated half-life parameters for all attack types to the noise reduction module for modeling and analysis. Network security devices also transmit traffic and tag information to the noise reduction module. The analyzer module analyzes the alarm information transmitted from the converter module to obtain relevant noise reduction parameters, which are then sent to the noise reduction module for deployment. Based on the half-life parameters sent by the analyzer module and the traffic, tag information, and maximum attack value sent by the network security device, the noise reduction module performs a security status assessment and proactively intercepts abnormal traffic, achieving the noise reduction effect. Figure 4 The diagram shows the overall architecture of the traffic data processing system based on active noise reduction provided by this invention. The deployment methods for modules such as the noise reducer, converter, and analyzer can be found in the diagram. Figure 4 As shown.

[0150] In this invention, the concept of attack half-life is proposed. The attack half-life is used as an important parameter to process traffic data. Based on the attack half-life and analysis, the maximum number of attacks for each type of network attack is obtained, and then the half-life parameters for all types of network attack are obtained. This enables the analysis of the attack behavior cycle, and the security status of the current attack behavior can be determined based on the half-life parameters, thereby achieving active noise reduction.

[0151] In the active noise reduction process, the threat assessment of network security devices is mainly based on the half-life function, attack distribution status, and attack duration. Network traffic is then blocked based on whether the threat threshold is exceeded. This threat assessment is primarily related to attack intensity; the greater the deviation of the threat IP traffic from normal traffic, the stronger the blocking force. This invention achieves active noise reduction of traffic data by proactively processing network traffic, which can reduce the number of device alarms and accurately identify the actual threat behavior of current security devices by combining attack half-life.

[0152] The traffic data processing system based on active noise reduction provided by this invention calculates the comprehensive traffic data impact of a network security device at the current moment by using the maximum number of attacks and the attack half-life of all types of network attacks received by the network security device within a preset period. Then, when it is determined that the comprehensive traffic data impact is greater than a preset impact threshold, the system performs corresponding active noise reduction processing on the traffic data of the network security device, thereby reducing the alarm volume of the network security device and accurately identifying the actual threat behavior of the current security device.

[0153] The system provided by this invention is used to execute the above-described method embodiments. For specific processes and details, please refer to the above embodiments, which will not be repeated here.

[0154] Figure 5 This is a schematic diagram of the structure of the electronic device provided by the present invention, such as... Figure 5 As shown, the electronic device may include: a processor 501, a communications interface 502, a memory 503, and a communication bus 504, wherein the processor 501, the communications interface 502, and the memory 503 communicate with each other through the communication bus 504. The processor 501 can call logic instructions in the memory 503 to execute a traffic data processing method based on active noise reduction. This method includes: acquiring alarm information data generated by a network security device at the current moment; determining, based on the alarm information data, the maximum number of attacks corresponding to each type of network attack received by the network security device within a preset period, and the attack half-life corresponding to each type of network attack; and calculating the comprehensive traffic data impact of the network security device at the current moment based on the maximum number of attacks and the attack half-life for all network attack types; and performing corresponding active noise reduction processing on the traffic data of the network security device if the comprehensive traffic data impact is determined to be greater than a preset impact threshold. The maximum number of attacks is obtained based on the number of attacks received by the network security device at various historical moments within the preset period; the attack half-life represents the time required for the number of attacks to reach half of the corresponding maximum number of attacks when the network security device is attacked within the preset period.

[0155] Furthermore, the logical instructions in the aforementioned memory 503 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0156] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions, wherein when the program instructions are executed by a computer, the computer is able to execute the traffic data processing method based on active noise reduction provided by the above methods, the method comprising: acquiring alarm information data generated by a network security device at the current moment; determining, based on the alarm information data, the maximum number of network attacks corresponding to each type of network attack received by the network security device within a preset period, and the attack half-life corresponding to each type of network attack, and calculating the comprehensive traffic data impact degree of the network security device at the current moment based on the maximum number of network attacks and the attack half-life of all network attack types; and performing corresponding active noise reduction processing on the traffic data of the network security device when it is determined that the comprehensive traffic data impact degree is greater than a preset impact degree threshold; wherein, the maximum number of attacks is obtained based on the number of attacks received by the network security device at each historical moment within a preset period; the attack half-life represents the time length required for the number of attacks to reach half of the corresponding maximum number of attacks when the network security device is attacked within a preset period.

[0157] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program is implemented to perform the traffic data processing method based on active noise reduction provided in the above embodiments. The method includes: acquiring alarm information data generated by a network security device at a current moment; determining, based on the alarm information data, the maximum number of network attacks corresponding to each type of network attack received by the network security device within a preset period, and the attack half-life of each type of network attack; and calculating the comprehensive traffic data impact degree of the network security device at the current moment based on the maximum number of network attacks and the attack half-life of all network attack types; and performing corresponding active noise reduction processing on the traffic data of the network security device when the comprehensive traffic data impact degree is determined to be greater than a preset impact degree threshold; wherein, the maximum number of attacks is obtained based on the number of attacks received by the network security device at each historical moment within a preset period; and the attack half-life represents the time length required for the number of attacks to reach half of the corresponding maximum number of attacks when the network security device is attacked within a preset period.

[0158] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0159] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0160] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A traffic data processing method based on active noise reduction, characterized in that, include: Obtain alarm information data generated by network security devices at the current moment; Based on the alarm information data, determine the maximum number of network attacks corresponding to each type of network attack that the network security device receives within a preset period, as well as the attack half-life of each type of network attack. Based on the maximum number of network attacks and the attack half-life of all network attack types, calculate the comprehensive traffic data impact of the network security device at the current moment. If the impact of the comprehensive traffic data is determined to be greater than a preset impact threshold, the traffic data of the network security device is subjected to corresponding active noise reduction processing. The maximum number of attacks is obtained based on the number of attacks received by the network security device at various historical moments within a preset period; the attack half-life represents the time required for the number of attacks to reach half of the corresponding maximum number of attacks when the network security device is attacked within a preset period.

2. The traffic data processing method based on active noise reduction according to claim 1, characterized in that, The method further includes: Obtain the cumulative number of times the network security device has been attacked by each type of network attack at each historical moment within a preset period; Based on a quadratic function, and according to the cumulative number of attacks at each historical moment, the attack cycle function of each type of network attack is fitted to obtain the attack cycle function of each type of network attack. Based on the attack cycle function, the maximum and minimum cumulative number of attacks for each type of network attack within a preset period are determined, and the maximum cumulative number of attacks is taken as the maximum number of attacks for the corresponding type of network attack. The standard attack value for each type of network attack is calculated based on the difference between the maximum cumulative number of attacks and the minimum cumulative number of attacks. Based on the attack cycle function and the attack quantity standard value, the attack half-life of each type of network attack is calculated, and the attack half-life parameter function is constructed based on the attack half-life and the maximum number of attacks.

3. The traffic data processing method based on active noise reduction according to claim 2, characterized in that, The calculation of the comprehensive traffic data impact of the network security device at the current moment, based on the maximum number of attacks and the attack half-life of all network attack types, includes: Based on the comprehensive traffic data impact formula, the comprehensive traffic data impact of the network security device at the current moment is calculated according to the maximum number of attacks and the attack half-life of all network attack types. The comprehensive traffic data impact formula is as follows: in, Indicates the overall impact of traffic data. Indicates the current moment. Indicates the first i The maximum number of attacks corresponding to a network attack type. Indicates the first i The attack half-life corresponding to the type of network attack is as follows: C This indicates that the network security device includes [the following] within the current preset period. C Network attacks of various types.

4. The traffic data processing method based on active noise reduction according to claim 2, characterized in that, When the impact of the comprehensive traffic data is determined to be greater than a preset impact threshold, the active noise reduction processing of the traffic data of the network security device includes: If the influence of the comprehensive traffic data is determined to be greater than a preset influence threshold, it is determined whether the difference between the influence of the comprehensive traffic data and the preset influence threshold is less than a preset influence difference. If the influence difference is greater than or equal to the preset influence difference, a traffic data blocking operation is performed on the network security device. If the impact difference is less than the preset impact difference, a random blocking operation is performed on the traffic data generated by the corresponding attack source in the network security device, wherein the attack source includes the address information of the sending end of the network attack; The method further includes: If the overall traffic data impact is determined to be less than or equal to the preset impact threshold, a traffic data passage operation is performed on the network security device.

5. The traffic data processing method based on active noise reduction according to claim 4, characterized in that, If the impact difference is less than the preset impact difference, a random blocking operation is performed on the traffic data generated by the target attack source in the network security device, including: If the impact difference is determined to be less than the preset impact difference, the number of historical attacks by the attack source attacking the network security device in the previous preset period is obtained. Based on the historical attack count, the attack half-life parameter function, and the maximum attack count, the attack cycle parameter of the attack source within the current preset cycle is calculated. If the attack cycle parameter is determined to be less than or equal to a preset attack cycle threshold, the blocking probability is calculated based on the difference between the attack cycle parameter and the preset attack cycle threshold, wherein the preset attack cycle threshold is half the duration corresponding to the preset cycle. Based on the traffic data generated by the attack source, a random number is generated corresponding to each traffic data, and traffic data whose random number is less than the blocking probability is blocked.

6. The traffic data processing method based on active noise reduction according to claim 1, characterized in that, The acquisition of alarm information data generated by network security devices at the current moment includes: Based on the network attacks launched by different attack sources against the network security device at the current moment, obtain the network attack type information, attack source address information, attack time point information within the current preset period, and attack count information corresponding to the attack time point information. The alarm information data is obtained based on the network attack type information, the attack source address information, the attack time point information, and the attack count information.

7. A traffic data processing system based on active noise reduction, characterized in that, include: The converter module is used to acquire alarm information data generated by network security devices at the current moment; The analyzer module is used to determine, based on the alarm information data, the maximum number of network attacks corresponding to each type of network attack that the network security device receives within a preset period, as well as the attack half-life of each type of network attack, and to calculate the comprehensive traffic data impact of the network security device at the current moment based on the maximum number of network attacks and the attack half-life of all network attack types. The noise reduction module is used to perform corresponding active noise reduction processing on the traffic data of the network security device when it is determined that the influence of the comprehensive traffic data is greater than a preset influence threshold. The maximum number of attacks is obtained based on the number of attacks received by the network security device at various historical moments within a preset period; the attack half-life represents the time required for the number of attacks to reach half of the corresponding maximum number of attacks when the network security device is attacked within a preset period.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the traffic data processing method based on active noise reduction as described in any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the traffic data processing method based on active noise reduction as described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the traffic data processing method based on active noise reduction as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Alarm reduction method and device, equipment and computer readable storage medium

    CN113315785A

  • Network alarm information clustering method based on attribute correlation

    CN113569116A