Network security operation service platform based on traffic threat analysis

By building a network security operation service platform based on traffic threat analysis, multi-dimensional feature analysis and real-time response to network traffic are achieved, and the lag problem of traditional platforms in the face of complex network threats is solved, and the accuracy and adaptability of threat detection are improved.

CN119341774BActive Publication Date: 2025-08-08ZHONGAN NETSHIELD (GUANGZHOU) INFORMATION TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411292645.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-14
Publication Date
2025-08-08
Estimated Expiration
2044-09-14

AI Technical Summary

Technical Problem

Existing network security operation platforms cannot handle and analyze network traffic threats in real time, and traditional traffic analysis methods lack adaptability and are difficult to deal with complex and diverse network attacks.

Method used

Build a network security operation service platform based on traffic threat analysis, obtain network traffic data in real time through the data acquisition module, build multi-dimensional threat analysis characteristics of the feature construction module, calculate threat analysis coefficients through the coefficient calculation module, and classify and respond to strategies through the threat analysis module.

Benefits of technology

It improves the accuracy of threat detection and real-time response, enhances the platform's adaptability, reduces the false alarm and missed alarm rates, and improves the reliability and overall protection capabilities of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119341774B_ABST
    Figure CN119341774B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security operation service platform based on traffic threat analysis, which relates to the field of network security technology. The platform includes a data acquisition module that acquires network traffic data in real time based on network traffic parameters, and divides the data into historical network traffic data and real-time network traffic data; a feature construction module that constructs traffic threat analysis features based on network traffic parameters, preprocesses the network traffic data, and calculates the value of the traffic threat analysis features based on the preprocessed network traffic data; a coefficient calculation module that combines traffic threat analysis features to form a feature vector, and calculates the traffic threat analysis coefficient through nonlinear combination and weight adjustment; a threat analysis module that sets a threat level threshold based on the threat analysis coefficient, classifies traffic threats, and executes a security response strategy based on the classification results. By combining historical and real-time network traffic data, a multi-dimensional threat feature analysis model is constructed, achieving accurate detection and graded response to traffic threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security operation service platform based on traffic threat analysis. Background Art

[0002] With the development of network technology and the popularization of its application, network security issues are becoming increasingly serious. Traditional network security protection measures mainly rely on static firewalls and intrusion detection systems, which are usually unable to respond to ever-changing network threats in a timely and effective manner. However, with the complexity and diversification of network traffic, threat detection technology based on traffic analysis has gradually become a research hotspot. Existing network threat detection methods based on traffic analysis usually rely on fixed feature extraction and analysis models, which are difficult to cope with complex network environments and changing threat types. However, when faced with traffic threats, existing network security operation platforms are usually unable to process and analyze them in real time, resulting in delayed threat response; traditional traffic analysis methods are mostly based on a single traffic feature, which makes it difficult to effectively detect complex and diverse network attacks; the analysis models of existing platforms are usually relatively fixed and lack adaptive capabilities, making it difficult to adapt to emerging network threats. Summary of the Invention

[0003] Based on the above-mentioned shortcomings of the prior art, the purpose of the present invention is to provide a network security operation service platform based on traffic threat analysis to solve the above-mentioned technical problems.

[0004] To achieve the above objectives, the present invention provides the following technical solutions: a network security operation service platform based on traffic threat analysis, comprising:

[0005] Data acquisition module: acquires network traffic data in real time according to network traffic parameters, and divides the network traffic data into historical network traffic data and real-time network traffic data;

[0006] Feature construction module: constructs traffic threat analysis features based on network traffic parameters, preprocesses the network traffic data, and calculates the value of the traffic threat analysis features based on the preprocessed network traffic data, wherein the traffic threat analysis features include traffic trend deviation features, traffic concentration features, traffic fluctuation response features, traffic loop features, and traffic packet sequence asymmetry features;

[0007] Coefficient calculation module: combines the traffic threat analysis features to form a feature vector, and calculates the traffic threat analysis coefficient through nonlinear combination and weight adjustment;

[0008] Threat analysis module: sets threat level thresholds based on threat analysis coefficients, classifies traffic threats, and executes security response strategies based on classification results.

[0009] The present invention is further configured such that the network traffic parameters include traffic rate, traffic density, traffic load, traffic intensity, transmission traffic, uplink traffic packet length and downlink traffic packet length.

[0010] The present invention is further configured to construct a traffic threat analysis feature based on network traffic parameters, including:

[0011] Calculate flow trend deviation characteristics based on flow rate;

[0012] Calculate traffic concentration characteristics based on traffic density and traffic load;

[0013] Calculate flow fluctuation response characteristics based on flow intensity;

[0014] Calculate traffic loop characteristics based on transmission traffic;

[0015] The asymmetric characteristics of the traffic packet sequence are calculated based on the uplink traffic packet length and the downlink traffic packet length.

[0016] The present invention is further configured such that the calculation logic of the flow trend deviation feature is: Among them, T deviation is the flow trend deviation characteristic, X(t) is the flow rate at time t, X baseline (t) is the historical benchmark flow rate under the same conditions as time t, T is the time period, κ is the adjustment coefficient, which is used to balance the influence of different calculation parts, and α is the nonlinear adjustment factor, which is used to control the steepness of the rate response function.

[0017] The present invention is further configured such that the flow concentration characteristic calculation logic is: Among them, T clustering is the traffic concentration characteristic, R i is the flow density of the i-th time period, T is the time period, n is the number of time periods in the time period, max(R(t)) and min(R(t)) are the maximum flow density and minimum flow density in the time period, β is the adjustment constant, C j is the traffic load at time j, ω is the frequency factor used to control the periodic change of the load, φ is the phase offset, which describes the relative offset of the load on the time axis, and m is the number of moments in the time period.

[0018] The present invention is further configured such that the calculation logic of the flow fluctuation response characteristic is: Among them, T fluctuation is the flow fluctuation response characteristic, Qt) is the flow intensity at time t, T is the time period, Q minis the minimum flow intensity within the time period, γ is the weight factor, and σ is the nonlinear response adjustment factor, which is used to control the response amplitude of flow fluctuations.

[0019] The present invention is further configured such that the calculation logic of the traffic loop feature is: Among them, T loopback is the traffic loop feature, K is the number of cycles, T is the time period, V(t) is the transmission flow at time t, τ is the cycle length, which is used to calculate the periodic repetitive behavior in the traffic sequence, λ is the exponential decay factor, δ is the characteristic adjustment parameter, and ξ is the phase adjustment parameter, which is used to perform phase compensation on the periodic signal.

[0020] The present invention is further configured such that the calculation logic of the asymmetric feature of the traffic packet sequence is: Among them, T asymmetry is the asymmetric feature of the traffic packet sequence, T is the time period, U(t) is the length of the uplink traffic packet at time t, D(t) is the length of the downlink traffic packet at time t, ∈ is a small constant used to prevent division by zero errors, ζ is the adjustment coefficient used to balance the overall influence of the feature item, N is the number of traffic packets, ΔU n is the time difference of the nth uplink packet, ΔD n is the time difference of the nth downlink packet.

[0021] The present invention is further configured such that the calculation logic of the traffic threat analysis coefficient is: Among them, λ is the traffic threat analysis coefficient, T i is the traffic threat analysis feature, w i is the feature weight, β jk is the feature interaction weight.

[0022] The present invention is further configured to set a threat level threshold according to a threat analysis coefficient, classify traffic threats, and execute a security response strategy according to the classification results, including:

[0023] When the traffic threat analysis coefficient is greater than the first threshold, the current traffic is marked as high-risk traffic, the traffic is blocked and an alarm is generated;

[0024] When the traffic threat analysis coefficient is less than or equal to the first threshold and greater than the second threshold, the current traffic is marked as medium-risk traffic, the traffic rate is limited, and manual judgment is performed;

[0025] When the traffic threat analysis coefficient is less than or equal to the second threshold, the current traffic is marked as low-risk traffic and allowed to pass.

[0026] The present invention provides a network security operation service platform based on traffic threat analysis, including a data acquisition module: acquiring network traffic data in real time according to network traffic parameters, and dividing the network traffic data into historical network traffic data and real-time network traffic data; a feature construction module: constructing traffic threat analysis features according to the network traffic parameters, preprocessing the network traffic data, and calculating the value of the traffic threat analysis features according to the preprocessed network traffic data, wherein the traffic threat analysis features include traffic trend deviation features, traffic concentration features, traffic fluctuation response features, traffic loop features, and traffic packet sequence asymmetry features; a coefficient calculation module: combining the traffic threat analysis features to form a feature vector, and calculating the traffic threat analysis coefficient through nonlinear combination and weight adjustment; a threat analysis module: setting a threat level threshold according to the threat analysis coefficient, classifying traffic threats, and executing a security response strategy according to the classification results. The beneficial effects produced include:

[0027] 1. Improve the accuracy of threat detection: This invention constructs a comprehensive traffic threat analysis model by extracting multi-dimensional features such as traffic trend deviation characteristics, traffic concentration characteristics, and traffic fluctuation response characteristics. It can effectively identify complex and diverse network attack behaviors and improve the accuracy of threat detection;

[0028] 2. Enhanced real-time response: The present invention integrates a real-time data acquisition module and a feature construction module. Through real-time analysis and calculation of network traffic data, it can timely adjust threat analysis strategies, achieve rapid response to network attacks, and reduce the response time of security incidents;

[0029] 3. Improved reliability and security: The platform of the present invention can dynamically adjust the analysis model parameters according to changes in network traffic threats, has adaptive capabilities, can effectively respond to new and constantly changing network threats, and improve the overall protection capabilities of the platform; through multi-dimensional analysis of traffic characteristics and parameter optimization, the present invention can accurately identify abnormal traffic, significantly reduce false alarm and missed alarm rates, and improve the reliability and security of threat analysis.

[0030] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without inventive efforts. In the drawings:

[0032] Figure 1 The figure is a structural diagram of a network security operation service platform based on traffic threat analysis according to an exemplary embodiment of the present invention. DETAILED DESCRIPTION

[0033] The following describes the embodiments of the present invention with reference to the accompanying drawings and preferred embodiments. Those skilled in the art will readily appreciate the other advantages and benefits of the present invention from the disclosure herein. The present invention may also be implemented or applied through various other specific embodiments, and the various details in this specification may be modified or altered based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are intended only to illustrate the present invention and are not intended to limit the scope of protection of the present invention.

[0034] It should be noted that the illustrations provided in the following embodiments are merely schematic illustrations of the basic concept of the present invention. Therefore, the illustrations only show components related to the present invention and are not drawn according to the number, shape, and size of components in actual implementation. In actual implementation, the type, quantity, and proportion of each component may be changed arbitrarily, and the component layout may also be more complex.

[0035] In the following description, numerous details are discussed to provide a more thorough explanation of the embodiments of the present invention. However, it will be apparent to those skilled in the art that the embodiments of the present invention may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring the embodiments of the present invention.

[0036] Network security operation service platform based on traffic threat analysis, such as Figure 1 As shown, including:

[0037] Data acquisition module: acquires network traffic data in real time according to network traffic parameters, and divides the network traffic data into historical network traffic data and real-time network traffic data;

[0038] Feature construction module: constructs traffic threat analysis features based on network traffic parameters, preprocesses the network traffic data, and calculates the value of the traffic threat analysis features based on the preprocessed network traffic data, wherein the traffic threat analysis features include traffic trend deviation features, traffic concentration features, traffic fluctuation response features, traffic loop features, and traffic packet sequence asymmetry features;

[0039] Coefficient calculation module: combines the traffic threat analysis features to form a feature vector, and calculates the traffic threat analysis coefficient through nonlinear combination and weight adjustment;

[0040] Threat analysis module: sets threat level thresholds based on threat analysis coefficients, classifies traffic threats, and executes security response strategies based on classification results.

[0041] Specifically, the data acquisition module acquires network traffic data in real time and categorizes the data according to preset network traffic parameters. Traffic data is divided into historical network traffic data and real-time network traffic data. Historical network traffic data is used to establish a baseline model to help detect and identify anomalies in current traffic; real-time network traffic data is used for immediate analysis and response. The present invention further provides that the network traffic parameters include traffic rate, traffic density, traffic load, traffic intensity, transmission traffic, upstream traffic packet length, and downstream traffic packet length. Specifically, traffic rate refers to the amount of data transmitted through a network node or link per unit time. The traffic rate is calculated by counting the number of bytes of all packets passing through the network per unit time. The calculation method is: traffic rate = total data volume / time interval. Traffic density indicates the concentration of traffic per unit time and space, reflecting the aggregation of traffic in a specific time period. It is calculated by calculating the distribution of traffic within a unit time window, taking into account the changes in traffic in time and space. The calculation method is: traffic density = traffic rate / (effective time window × spatial dimension). Traffic load is a measure of the current load of a network node or link, reflecting the stress state of the network device or link. It is determined by measuring the amount of data transmitted, the number of connections, or the packet processing rate within a specific time period. The unit is usually bytes / second or number of connections. The calculation method is: traffic load = number of active connections × average packet length / packet processing rate. Traffic intensity refers to the transmission intensity in the network within a certain time range, reflecting the overall traffic scale and load level over a period of time. It is calculated by accumulating the amount of data transmitted and the number of active connections per unit time. The calculation method is: The connection strength is the traffic value of a single connection, and the transmission time is the duration. The transmission flow refers to the amount of data in a specific transmission path or session. It is used to evaluate the data scale of a certain transmission task. It is calculated by recording the cumulative size of data packets during a transmission process: Among them, the size of each data packet is the number of bytes of a single data packet in a transmission task; the uplink traffic packet length refers to the size of a single data packet from the client to the server, which is used to analyze the traffic characteristics in the upload direction. By measuring the size of all data packets in the uplink direction, the calculation method is: uplink traffic packet length = total uplink data volume / number of uplink packets; the downlink traffic packet length refers to the size of a single data packet from the server to the client, which is used to analyze the traffic characteristics in the download direction. By measuring the size of all data packets in the downlink direction, the calculation method is: downlink traffic packet length = total downlink data volume / number of downlink packets;

[0042] The feature construction module constructs traffic threat analysis features based on network traffic parameters and preprocesses network traffic data. The preprocessed data is used to calculate the values of various traffic threat analysis features to ensure data quality and analysis accuracy. The present invention is further configured to construct traffic threat analysis features based on network traffic parameters, including:

[0043] The flow trend deviation feature is calculated based on the flow rate. The present invention is further configured such that the calculation logic of the flow trend deviation feature is: Among them, T deviation is the flow trend deviation characteristic, X(t) is the flow rate at time t, X baseline (t) is the historical baseline traffic rate under the same conditions as time t, T is the time period, κ is the adjustment coefficient, which is used to balance the influence of different calculation parts, and α is the nonlinear adjustment factor, which is used to control the steepness of the rate response function. Specifically, the above calculation logic is used to calculate the deviation characteristics of the traffic rate trend, with the aim of identifying the difference between the current traffic and the historical baseline traffic, especially when the traffic trend deviates significantly, which helps to detect potential abnormal behaviors such as network attacks, traffic surges, etc. The calculation process consists of two parts: the first part measures the trend change of the traffic rate through the second-order derivative; the second part uses the first-order derivative combined with the nonlinear function for further adjustment to capture the nonlinear characteristics of the traffic response; the first part By comparing the second-order derivative, we can identify the degree of deviation between the acceleration of the current flow rate and the historical benchmark. A larger deviation means a drastic change in the flow trend, which may be a signal of a potential threat; Part II First-order derivatives are combined with nonlinear response functions to capture subtle characteristics of traffic rate changes. The adjustment coefficient κ adjusts the coefficient of the calculated balance, with a value range of [0.1, 10], adjusted according to the sensitivity of traffic fluctuations. The nonlinear adjustment factor α controls the steepness of the nonlinear function, affecting the strength of the response adjustment, with a value range of [0.5, 5], ensuring that the adjustment response is neither too flat nor too sensitive. By comparing second-order derivatives, the difference between the current traffic rate and historical trends can be accurately identified, and abnormal behavior can be quickly detected. Combined with the nonlinear adjustment function of the first-order derivative, it can effectively capture sudden changes, such as instantaneous traffic surges or decelerations, allowing the platform to provide timely warnings and responses.

[0044] The flow concentration characteristic is calculated based on the flow density and the flow load. The present invention is further configured such that the flow concentration characteristic calculation logic is: Among them, T clustering is the traffic concentration characteristic, R i is the flow density of the i-th time period, T is the time period, n is the number of time periods in the time period, max(R(t)) and min(R(t)) are the maximum flow density and minimum flow density in the time period, β is the adjustment constant, C j is the traffic load at time j, ω is the frequency factor used to control the periodic change of the load, φ is the phase offset, which describes the relative offset of the load on the time axis, and m is the number of moments in the time period. Specifically, the above calculation logic is used to calculate the traffic concentration characteristics, with the aim of evaluating the concentration of network traffic in time and space, and helping to identify traffic aggregation effects, such as network congestion, high-frequency request density and other phenomena. The calculation process is divided into two parts: the first part analyzes the concentration of traffic through the combination of traffic density and load, and the second part captures the periodic fluctuation of traffic load and its impact on aggregation through periodic adjustment factors; the first part The traffic density and load concentration within a time period are calculated. Part II The impact of periodic load changes on traffic concentration is evaluated by adjusting the sine and cosine function factors, combined with the relative offset of the load. The adjustment constant β is used to balance the influence of different terms in the calculation, with a value range of [0.1, 10]. The frequency factor ω is used to adjust the fluctuation rate of the periodic function, affecting the response of the concentration characteristic to periodic changes, with a value range of [0.01, 1]. The phase offset φ is used to describe the position of the load change on the time axis and adjust the phase of the traffic fluctuation, with a value range of [0, 2π]. The above calculation logic can accurately capture the degree of traffic concentration within a time period and effectively identify high load or traffic concentration behavior, such as DDoS attacks and sudden requests. By adjusting the frequency factor and phase offset, periodic load fluctuations can be identified, helping to detect peak work periods or abnormal periodic behavior, and improving the ability to distinguish normal and abnormal patterns.

[0045] The flow fluctuation response characteristic is calculated according to the flow intensity. The present invention is further configured such that the calculation logic of the flow fluctuation response characteristic is: Among them, T fluctuation is the flow fluctuation response characteristic, Q(t) is the flow intensity at time t, T is the time period, Q min is the minimum traffic intensity within the time period, γ is the weight factor, and σ is the nonlinear response adjustment factor, which is used to control the response amplitude of traffic fluctuations. The above calculation logic calculates the traffic fluctuation response characteristics, with the aim of evaluating the fluctuation intensity and responsiveness of network traffic in a short period of time. This feature combines the third-order change of traffic intensity with nonlinear response adjustment, and reflects the instantaneous response characteristics of traffic through maximum change and volatility. The formula is mainly divided into two parts: the first part evaluates the sharp change of traffic intensity, and the second part uses the nonlinear adjustment factor to capture the response amplitude of traffic, with particular attention to the sensitivity near low traffic intensity; the first part The maximum value of the third-order derivative of the flow intensity is calculated, which partially reflects the rapid change or sharp fluctuation of the flow in the time dimension. The second part A combination of the first-order derivative and the nonlinear adjustment function is used to adjust the response amplitude of the flow rate, emphasizing the detailed capture of fluctuations. The weight factor γ is used to adjust the influence of the maximum value of the third-order derivative on the total feature, and the value range is [0.1, 10] to balance the relationship between sharp fluctuations and overall fluctuation response. The nonlinear response adjustment factor σ controls the nonlinear degree of the flow fluctuation response, making the feature more sensitive to fluctuations within a specific intensity range, and the value range is [0.5, 5].

[0046] The traffic loop feature is calculated based on the transmission traffic. The present invention is further configured such that the calculation logic of the traffic loop feature is: Among them, T loopbackis the traffic loop feature, K is the number of cycles, T is the time period, V(t) is the transmission traffic at time t, τ is the cycle length, which is used to calculate the periodic repetitive behavior in the traffic sequence, λ is the exponential decay factor, δ is the feature adjustment parameter, and ξ is the phase adjustment parameter, which is used to perform phase compensation on the periodic signal. Specifically, the above calculation logic calculates the traffic loop feature, which is used to detect periodic repetitive behaviors in network traffic, such as traffic cycles, repeated requests, etc. The feature calculation combines period detection and compensation for cyclic signals. It captures the intensity and phase offset of the loop behavior by weighted summation of repetitive behaviors in different cycles in the traffic sequence and combining it with a sinusoidal adjustment function. The formula is divided into two parts: the first part detects the loop effect by periodic superposition of traffic intensity, and the second part reflects the phase offset of the periodic signal by sinusoidal function compensation; the first part The periodic overlap of traffic transmission is calculated, and the repeatability of traffic is detected by weighted superposition of different periods. Part II The sine function is used to compensate the periodic signal, focusing on reflecting the phase offset of the periodic signal. The exponential decay factor λ controls the weight of the periodic superposition, adjusts the contribution of the long period to the feature, and prevents excessive impact on the current detection. The value range is [0.1, 5]. The feature adjustment parameter δ is used to adjust the sine compensation amount to balance the influence of the periodic signal on the detection feature. The value range is [0.1, 10]. The phase adjustment parameter ξ controls the intensity of the phase compensation so that the detection of the periodic signal can take into account the phase change over time. The value range is [0, 2π].

[0047] The asymmetric characteristic of the traffic packet sequence is calculated based on the uplink traffic packet length and the downlink traffic packet length. The present invention is further configured such that the calculation logic of the asymmetric characteristic of the traffic packet sequence is: Among them, T asymmetry is the asymmetric feature of the traffic packet sequence, T is the time period, U(t) is the length of the uplink traffic packet at time t, D(t is the length of the downlink traffic packet at time t, ∈ is a small constant used to prevent zero division errors, ζ is the adjustment coefficient used to balance the overall influence of the feature item, N is the number of traffic packets, and ΔU n is the time difference of the nth uplink packet, ΔD n is the time difference of the nth downlink packet. Specifically, the above calculation logic calculates the asymmetric characteristics of the traffic packet sequence, with the purpose of evaluating the asymmetry of network traffic in the uplink and downlink directions, and detecting abnormal data transmission behaviors such as atypical data packet transmission, traffic amplification attacks, etc. by analyzing the uplink and downlink packet lengths and time differences. This feature calculation combines the analysis of packet length asymmetry and time differences, and is divided into two parts: the first part detects the difference in uplink and downlink packet lengths, and the second part evaluates the time difference of uplink and downlink data packets to reflect the dynamic characteristics of traffic transmission; the first part The asymmetry of the uplink and downlink packet lengths in the time period is calculated, and the contribution of the packet length difference to the asymmetry is analyzed. Part II The time difference between uplink and downlink packets is used to measure the transmission asymmetry of uplink and downlink data packets; the small constant ∈ is a small value to ensure the stability of calculation, and its value range is [10 -9 ,10 -6 ], the adjustment coefficient ζ is used to adjust the overall impact of the time difference on the asymmetric feature, and its value range is [0.1, 10]. By detecting the difference between the uplink and downlink packet lengths and the time difference, this feature can effectively identify abnormal asymmetry in the traffic direction, such as network amplification attacks and delay attacks. A detailed analysis of the time difference between uplink and downlink data packets helps to discover potential transmission delays and timing asymmetry problems, thereby ensuring the normal operation of the network.

[0048] The present invention is further configured such that the calculation logic of the traffic threat analysis coefficient is: Among them, λ is the traffic threat analysis coefficient, T i is the traffic threat analysis feature, w i is the feature weight, β jk is the weight of the feature interaction term. Specifically, the above calculation logic is used to calculate the traffic threat analysis coefficient, the purpose of which is to combine the influence of multiple traffic threat analysis features and generate an overall threat assessment index through nonlinear combination and feature interaction terms. This index is used to evaluate the potential threat level of network traffic. The formula combines the contribution of a single feature (expressed by weighted summation) and the interaction effect between features (expressed in the form of quadratic terms), and then uses the Logistic function for nonlinear mapping to obtain the threat analysis coefficient; the first part The weighted sum of each traffic threat analysis feature is calculated, where w i The weight of each feature. By assigning different weight values to different features, the relative importance of each feature in the overall threat assessment is reflected. The second part It represents the interaction between features. This part is used to capture the correlation effects between features, especially the complex behavior patterns that may arise when multiple features work together. Through the comprehensive evaluation and nonlinear combination of multiple traffic threat analysis features, it can more accurately and comprehensively reflect the overall threat level of network traffic and avoid misjudgments caused by a single feature. The introduction of feature interaction terms enables the formula to identify and capture complex threat patterns, especially those abnormal behaviors that only appear when multiple features work together.

[0049] The present invention is further configured to set a threat level threshold according to a threat analysis coefficient, classify traffic threats, and execute a security response strategy according to the classification results, including:

[0050] When the traffic threat analysis coefficient is greater than the first threshold, the current traffic is marked as high-risk traffic, the traffic is blocked and an alarm is generated;

[0051] When the traffic threat analysis coefficient is less than or equal to the first threshold and greater than the second threshold, the current traffic is marked as medium-risk traffic, the traffic rate is limited, and manual judgment is performed;

[0052] When the traffic threat analysis coefficient is less than or equal to the second threshold, the current traffic is marked as low-risk traffic and allowed to pass. Specifically, when the traffic threat analysis coefficient is greater than the first threshold, it indicates that the current traffic may pose a serious security risk, such as malicious attacks, data leaks, etc. In this case, the traffic is marked as high-risk traffic. Response measures: Immediately block the traffic to prevent it from further affecting network security, and at the same time trigger an alarm mechanism to warn the security team so that emergency response actions can be taken quickly.

[0053] When the traffic threat analysis coefficient is between the first and second thresholds, it indicates that the current traffic is somewhat abnormal but not serious, and is considered medium risk. This type of traffic may be due to non-malicious abnormal behavior or potential threats. Response measures: Mark the traffic as medium-risk traffic and implement rate limiting to reduce its impact on the network. Further manual determination is made to determine whether further blocking or allowing is required.

[0054] When the traffic threat analysis coefficient is less than or equal to the second threshold, it means that the current traffic is basically normal and there is no obvious security risk. Response measures: Mark the traffic as low-risk traffic, allow the traffic to pass normally, and ensure business continuity. By grading the traffic threat coefficient, it is possible to achieve accurate response to traffic, thereby improving the effectiveness of network defense and preventing serious security consequences caused by high-risk traffic. By flexibly adjusting the threshold, the system can adapt to different network environments and threat changes, ensuring that security policies always match actual risks. By setting up multi-level risk classification, the misjudgment problem caused by simple blocking is avoided, ensuring the passage of normal business traffic, and at the same time, performing necessary control on suspicious traffic.

[0055] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0056] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0057] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0058] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0059] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0060] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0061] In the several embodiments provided in this application, it should be understood that the disclosed system can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0062] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0063] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0064] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0065] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A network security operation service platform based on traffic threat analysis, characterized by: include: Data acquisition module: acquires network traffic data in real time according to network traffic parameters, and divides the network traffic data into historical network traffic data and real-time network traffic data; The network traffic parameters include traffic rate, traffic density, traffic load, traffic intensity, transmission traffic, uplink traffic packet length and downlink traffic packet length; Feature construction module: constructs traffic threat analysis features according to network traffic parameters, preprocesses the network traffic data, and calculates the value of the traffic threat analysis features according to the preprocessed network traffic data, wherein the traffic threat analysis features include traffic trend deviation features, traffic concentration features, traffic fluctuation response features, traffic loop features, and traffic packet sequence asymmetry features, including: calculating the traffic trend deviation features according to the traffic rate; calculating the traffic concentration features according to the traffic density and traffic load; calculating the traffic fluctuation response features according to the traffic intensity; calculating the traffic loop features according to the transmission traffic; calculating the traffic packet sequence asymmetry features according to the uplink traffic packet length and the downlink traffic packet length; Coefficient calculation module: combines the traffic threat analysis features to form a feature vector, and calculates the traffic threat analysis coefficient through nonlinear combination and feature interaction terms; Threat analysis module: sets threat level thresholds based on threat analysis coefficients, classifies traffic threats, and executes security response strategies based on classification results.

2. The network security operation service platform based on traffic threat analysis according to claim 1 is characterized in that: The calculation logic of the traffic trend deviation feature is: ,in, is the flow trend deviation characteristic, for The flow rate at the time, For The historical benchmark traffic rate under the same conditions at the time, is the time period, is the adjustment coefficient used to balance the impact of different calculation parts. It is a nonlinear adjustment factor used to control the steepness of the rate response function.

3. The network security operation service platform based on traffic threat analysis according to claim 1 is characterized in that: The calculation logic of the traffic concentration characteristic is: ,in, is the traffic concentration characteristic, For the The traffic density in each time period, is the time period, is the number of time periods in the time period, and are the maximum flow density and minimum flow density within the time period, is the adjustment constant, for Traffic load at the moment, is the frequency factor, which is used to control the periodic change of the load. is the phase offset, which describes the relative offset of the load on the time axis. is the number of moments in the time period.

4. The network security operation service platform based on traffic threat analysis according to claim 1 is characterized in that: The calculation logic of the flow fluctuation response characteristic is: ,in, is the flow fluctuation response characteristic, for Traffic intensity at the moment, is the time period, is the minimum flow intensity within the time period, is the weight factor, It is a nonlinear response adjustment factor used to control the response amplitude of flow fluctuation.

5. The network security operation service platform based on traffic threat analysis according to claim 1 is characterized in that: The calculation logic of the traffic loop feature is: ,in, is the traffic loop feature, is the number of cycles, is the time period, for The transmission flow at any moment, is the cycle length, which is used to calculate the periodic repetitive behavior in the traffic sequence. is the exponential decay factor, is the feature adjustment parameter, is a phase adjustment parameter used to perform phase compensation on periodic signals.

6. The network security operation service platform based on traffic threat analysis according to claim 1 is characterized in that: The calculation logic of the asymmetric feature of the traffic packet sequence is: ,in, is the asymmetric characteristic of the traffic packet sequence, is the time period, for Uplink traffic packet length at the time, for The downlink traffic packet length at the time, is a small constant used to prevent division by zero errors. is the adjustment coefficient, which is used to balance the overall influence of the feature items. is the number of traffic packets, For the The time difference of uplink packets, For the The time difference of the downlink packets.

7. The network security operation service platform based on traffic threat analysis according to claim 6 is characterized in that: The calculation logic of the traffic threat analysis coefficient is: ,in, is the traffic threat analysis coefficient, 、 and Analyze traffic threat characteristics. is the feature weight, is the feature interaction weight.

8. The network security operation service platform based on traffic threat analysis according to claim 7 is characterized in that: Set threat level thresholds based on threat analysis coefficients, classify traffic threats, and implement security response strategies based on the classification results, including: When the traffic threat analysis coefficient is greater than the first threshold, the current traffic is marked as high-risk traffic, the traffic is blocked and an alarm is generated; When the traffic threat analysis coefficient is less than or equal to the first threshold and greater than the second threshold, the current traffic is marked as medium-risk traffic, the traffic rate is limited, and manual judgment is performed; When the traffic threat analysis coefficient is less than or equal to the second threshold, the current traffic is marked as low-risk traffic and allowed to pass.

Citation Information

Patent Citations

  • Advanced sustainable threat tracing method and system, computer equipment and storage medium

    CN111800412A