A network traffic detection method and system

By extracting abnormal traffic tokens under the network protocol and generating an alarm map, the problem of difficulty in detecting new attacks in the existing technology is solved, effectively identifying and early warning of new attacks is achieved, and alarm efficiency of network security is improved.

CN119382956BActive Publication Date: 2025-06-03CHINA NORTH IND CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411473429.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-22
Publication Date
2025-06-03
Estimated Expiration
2044-10-22

AI Technical Summary

Technical Problem

The existing anomaly classification attack detection scheme is difficult to effectively detect new attack types, and the detection effect based on statistical methods is poor and the false alarm rate is high.

Method used

By analyzing network traffic under each network protocol, extracting tokens of abnormal traffic, and using these tokens to match the second network traffic, generating an alarm map to identify abnormal traffic, and predicting possible next abnormal traffic.

Benefits of technology

It realizes effective identification and security alarms for new attack types, reduces the false alarm and missed rate, and provides security protection in advance through the warning mechanism, improving alarm efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119382956B_ABST
    Figure CN119382956B_ABST
Patent Text Reader

Abstract

The present invention relates to a network traffic detection method and system, belonging to the field of network security technology. According to the analysis results of the first network traffic under each network protocol, the present invention obtains the tokens of the abnormal traffic of each network protocol; uses the tokens to match the second network traffic under each network protocol, and in response to matching the target alarm data under any protocol by using the tokens, mounts the target node corresponding to the target alarm data on the alarm graph; determines the second node link matching in the alarm graph according to the first node link containing the target node in the alarm graph, the second node link contains a complete network protocol link, and determines whether there is a next connected node for the node with the any protocol in the second node link. If there is a next node, a pre-alarm message is generated according to the network protocol corresponding to the next node. The present invention can perform security protection in advance and improve the alarm efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to a network traffic detection method and system. Background Art

[0002] With the rapid development of information technology, the network has become an indispensable part of people's lives and work. The growth of network traffic has brought rich information resources and convenient communication methods, but it has also been accompanied by a series of security risks, such as network attacks, malware, and illegal access. These security incidents pose a serious threat to personal privacy, corporate secrets, and national security. Therefore, how to effectively detect abnormal network traffic has become an urgent problem to be solved in the field of network security. Traditional detection methods are mainly based on rule matching and statistical learning, but in the face of complex and changing network environments and massive data, these methods show certain limitations.

[0003] The existing abnormal classification attack detection schemes have the following problems:

[0004] They only detect single or several attack methods, such as network scanning, SQL injection, and cross-site scripting attack (XSS), and thus are helpless against new attack types.

[0005] Attack field extraction only focuses on abnormal characters or keywords in specific fields, for example, extracting specific strings from SQL injection. This method may not be able to respond to new attacks in a timely manner, resulting in a relatively high number of false positives and false negatives.

[0006] The detection based on statistical methods analyzes through traffic parameters (such as the number of data packets, bytes, traffic rate, etc.), and there are problems of poor detection effect and high false positive rate. These methods identify abnormalities through statistical comparison or rule formulation, but perform limitedly in complex environments. Summary of the Invention

[0007] (1) Technical Problems to be Solved

[0008] The technical problem to be solved by the present invention is how to provide a network traffic detection method and system to solve the above problems existing in the existing abnormal classification attack detection schemes.

[0009] (2) Technical Solutions

[0010] To solve the above technical problems, the present invention proposes a network traffic detection method, and the method includes:

[0011] According to the analysis results of the first network traffic under each network protocol, obtain the tokens of the abnormal traffic of each network protocol; the network protocols include: the protocols corresponding to the information collection stage, vulnerability scanning stage, network attack stage, and data stealing stage;

[0012] Match the second network traffic under each of the network protocols using the token. In response to matching the target alarm data under any protocol using the token, mount the target node corresponding to the target alarm data on the alarm graph. The alarm graph includes at least one alarm data node, and the alarm data nodes are connected in the order of the same source IP, the same destination IP, the same source port, the same destination port, and chronological order.

[0013] According to the first node link in the alarm graph that includes the target node, determine the matching second node link in the alarm graph. The second node link includes a complete network protocol link, and determine whether there is a next node connected to the node with the arbitrary protocol in the second node link. If there is such a next node, generate a pre-alarm message according to the network protocol corresponding to the next node.

[0014] The present invention provides a network traffic detection system, which includes:

[0015] A token acquisition module, which obtains the tokens of the abnormal traffic of each network protocol according to the analysis results of the first network traffic under each network protocol. The network protocols include the protocols corresponding to the information collection stage, the vulnerability scanning stage, the network attack stage, and the data stealing stage.

[0016] An abnormal alarm and node mounting module, which matches the second network traffic under each network protocol using the token. In response to matching the target alarm data under any protocol using the token, mount the target node corresponding to the target alarm data on the alarm graph. The alarm graph includes at least one alarm data node, and the alarm data nodes are connected in the order of the same source IP, the same destination IP, the same source port, the same destination port, and chronological order.

[0017] A pre-alarm module, which determines the matching second node link in the alarm graph according to the first node link in the alarm graph that includes the target node. The second node link includes a complete network protocol link, and determines whether there is a next node connected to the node with the arbitrary protocol in the second node link. If there is such a next node, generate a pre-alarm message according to the network protocol corresponding to the next node.

[0018] (III) Beneficial effects

[0019] The present invention provides a network traffic detection method and system. In the method of the present invention, tokens included in abnormal traffic under each network protocol can be summarized and learned, and the tokens are used to detect abnormal traffic under each network protocol, so that abnormal traffic can be effectively identified for new attack types, security alerts can be issued, and further, according to the detected alert data, the learned alert graph can be used to predict possible abnormal traffic in the next step for pre-alert, and security protection can be carried out in advance to improve the alert efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 It is a corresponding diagram of attack steps and network protocols of the present invention;

[0021] Figure 2 It is a schematic flowchart of a network traffic detection method shown in an embodiment of the present invention;

[0022] Figure 3 It is a schematic flowchart of a method for generating an attack graph of the present invention;

[0023] Figure 4 It is a schematic structural diagram of an attack graph of the present invention;

[0024] Figure 5 It is a schematic structural diagram of another attack graph of the present invention;

[0025] Figure 6 It is a schematic flowchart of a method for obtaining tokens of the present invention;

[0026] Figure 7 It is a schematic flowchart of a method for aggregating alerts of the present invention;

[0027] Figure 8 It is a schematic structural diagram of a network traffic detection system of the present invention;

[0028] Figure 9 It is a schematic diagram of an alert graph of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0029] To make the objectives, contents, and advantages of the present invention clearer, the following further describes the detailed embodiments of the present invention with reference to the drawings and embodiments.

[0030] The present invention provides a network traffic detection method, and the method includes:

[0031] According to the analysis result of the first network traffic under each network protocol, tokens of abnormal traffic of each network protocol are obtained; the network protocols include protocols corresponding to an information collection stage, a vulnerability scanning stage, a network attack stage, and a data stealing stage;

[0032] Match the second network traffic under each of the network protocols using the token. In response to matching the target alarm data under any protocol using the token, mount the target node corresponding to the target alarm data on the alarm graph; the alarm graph includes at least one alarm data node, and the alarm data nodes are connected in the order of the same source IP, the same destination IP, the same source port, the same destination port, and chronological order.

[0033] Determine the second node link that matches in the alarm graph according to the first node link containing the target node in the alarm graph. The second node link includes a complete network protocol link, and determine whether there is a next node connected to the node with the arbitrary protocol in the second node link. If there is such a next node, generate a pre-alarm message according to the network protocol corresponding to the next node.

[0034] Further, the method further includes:

[0035] Obtain at least one node link in the alarm graph;

[0036] For each node link, extract the information of each node included in the node link. The information includes attack protocol information, target IP information, and whether the attack is successful information;

[0037] Generate an attack graph corresponding to each node link according to the extracted information. The attack graph includes an attack target node, an attack tool node, an attack strategy node, an attack effect node, an attack ability node, and an attack event sequence; wherein, the target node includes the target IP information, the attack effect includes whether the attack is successful information, the attack tool node includes a set of attack protocol information, and the attack strategy node includes a set of attack protocol information arranged in chronological order; the attack ability node includes a set of business stages corresponding to the attack protocol information, and the attack event sequence includes a set of alarm data nodes arranged in chronological order;

[0038] Display the attack graph corresponding to each node link.

[0039] Further, the obtaining the tokens of the abnormal traffic of each network protocol according to the analysis result of the first network traffic under each network protocol includes:

[0040] For each network protocol, determine the fragments that appear repeatedly in the traffic determined to be suspicious traffic under the network protocol and reach the first threshold as the first token;

[0041] Select the second tokens with a false positive rate lower than the second threshold and / or a coverage rate higher than the third threshold among the first tokens as the tokens of the abnormal traffic of the network protocol; the false positive rate refers to the probability that the normal traffic containing the first token is misdetected as abnormal traffic; the coverage rate refers to the probability that the abnormal traffic containing the first token is indeed detected as abnormal traffic.

[0042] Further, after determining the first token, it further includes:

[0043] Remove the sub-tokens in the first token; the sub-token is a partial segment of the first token.

[0044] Further, the matching of the second network traffic under each network protocol by using the token includes:

[0045] Collect the first alarm data under each network protocol matched by using the token;

[0046] According to the preset alarm removal rule, remove the duplicate alarm data in the first alarm data to obtain the second alarm data;

[0047] For each network protocol, aggregate the second alarm data under the network protocol within the alarm retention duration corresponding to the network protocol;

[0048] In response to the aggregation duration of the second alarm data under any protocol reaching the alarm retention duration corresponding to the any protocol, determine the super alarm obtained by aggregation as the target alarm data under the any protocol matched by using the token.

[0049] Further, the method for adaptively adjusting the alarm retention duration includes:

[0050] Count the number of abnormal traffic under the network protocol per unit time;

[0051] Query the alarm duration corresponding to the number of abnormal traffic in the preset alarm retention duration template and determine it as the alarm retention duration corresponding to the network protocol; the alarm retention duration is between the first value and the second value.

[0052] Further, the aggregation of the second alarm data under the network protocol includes:

[0053] Aggregate in the order of the following conditions. If the aggregation is completed according to the condition with a higher sorting order, ignore the condition with a lower sorting order:

[0054] The network protocol type, source IP, and destination IP are all the same;

[0055] The source IP and the destination IP are the same;

[0056] The destination IP is the same;

[0057] The source IP is the same.

[0058] Further, the mounting of the target node corresponding to the target alarm data on the alarm graph includes:

[0059] Obtain the alarm graph;

[0060] Search for a first node in the alarm graph, where the source IP indicated by the first node is the same as the first source IP indicated by the target alarm data;

[0061] If the first node meeting the conditions is not found, determine the target node as an independent node;

[0062] If the first node meeting the conditions is found, search for a second node among the nodes connected to the first node, where the target IP included in the second node is the same as the first target IP indicated by the target alarm data;

[0063] If the second node meeting the conditions is not found, mount the target node on the first node;

[0064] If the second node meeting the conditions is found, search for a third node among the nodes connected to the second node, where the source port included in the third node is the same as the first source port indicated by the target alarm data;

[0065] If the third node meeting the conditions is not found, mount the target node on the second node;

[0066] If the third node meeting the conditions is found, search for a fourth node among the nodes connected to the third node, where the destination port included in the fourth node is the same as the first destination port indicated by the target alarm data;

[0067] If the fourth node meeting the conditions is not found, mount the target node on the third node;

[0068] If the fourth node meeting the conditions is found, in response to the alarm time of the fourth node being earlier, mount the target node on the fourth node.

[0069] Further, the determining of the second node link matching in the alarm graph according to the first node link including the target node in the alarm graph includes:

[0070] Obtain a first node link in the alarm graph that includes the target node;

[0071] According to the network protocol link indicated by the first node link, determine a second node link with the highest degree of repetition of the indicated network protocol link; the second node link corresponds to a composite attack scenario; the composite attack scenario includes multiple network protocols;

[0072] The step of determining whether there is a next node connected to the node with the arbitrary protocol in the second node link includes:

[0073] According to the position of the target node in the first node link, calculate the detection degree and / or matching degree corresponding to the target node; the detection degree refers to the proportion of the actually detected network protocols from the initial network protocol to the network protocol corresponding to the target node in the composite attack scenario when the network protocol corresponding to the target node is detected; the matching degree refers to the proportion of the detected network protocols in all the network protocols included in the composite attack scenario when the network protocol corresponding to the target node is detected.

[0074] In response to the detection degree reaching a fourth threshold and / or the matching degree reaching a fifth threshold, determine whether there is a next node connected to the node with the arbitrary protocol in the second node link.

[0075] The present invention also provides a network traffic detection system, and the system includes:

[0076] A token acquisition module, which obtains tokens of abnormal traffic of each network protocol according to the analysis results of the first network traffic under each network protocol; the network protocols include the protocols corresponding to the information collection stage, the vulnerability scanning stage, the network attack stage, and the data stealing stage;

[0077] An abnormal alarm and node mounting module, which matches the second network traffic under each network protocol by using the token, and in response to matching the target alarm data under any protocol by using the token, mounts the target node corresponding to the target alarm data on the alarm graph; the alarm graph includes at least one alarm data node, and the alarm data nodes are connected in the order of the same source IP, the same destination IP, the same source port, the same destination port, and the chronological order;

[0078] The pre-warning module determines a second node link that matches in the alarm spectrum according to the first node link containing the target node in the alarm spectrum. The second node link contains a complete network protocol link, and determines whether there is a next connected node among the nodes with any protocol in the second node link. If there is such a next node, pre-warning information is generated according to the network protocol corresponding to the next node.

[0079] Embodiment 1:

[0080] Regardless of the network attack method, generally, it will go through four attack stages: information collection stage, vulnerability scanning stage, vulnerability scanning stage, and network attack stage.

[0081] Information collection stage: It includes passive collection and active collection. It mainly collects the network information (domain name, IP address, network topology), system information (operating system version, network service version), and user information (user identifier, group identifier, shared resources, instant messaging software account, email account, etc.) of the target.

[0082] Vulnerability scanning stage: It is carried out after information collection. Through scanning means based on a vulnerability database, the security vulnerabilities of a specified computer system are detected to find exploitable vulnerabilities.

[0083] Network attack stage: After information collection and vulnerability scanning, the attacker uses the vulnerabilities in the target system or application to obtain initial access rights.

[0084] Data stealing stage: The attacker executes the ultimate goals such as stealing sensitive data, destroying system functions, or extortion. Tools are used to screen and filter data, and valuable information such as financial data, business secrets, and personal identity information is retained.

[0085] Each stage will correspond to its own network protocol. Please refer to Table 1, which is a corresponding table of network protocol and attack stage illustrated by the present invention.

[0086] Table 1 Protocols corresponding to each stage

[0087]

[0088] Among them, these four stages can include five attack steps: footprinting, scanning, penetration, privilege escalation, and stealing. Please refer to Figure 1 , Figure 1 which is a corresponding diagram of attack steps and network protocols shown by the present invention. As Figure 1As shown, the first row contains 5 attack steps in sequence from left to right. Usually, it takes 5 steps from left to right to complete a composite attack. Under each attack step, there is a column corresponding to network protocols, and each step requires at least one corresponding network protocol to complete communication. For example, the footprinting step corresponds to three network protocols: Fping, DNS, and Nmap ping. There are arrows between these network protocols, representing the association relationships between them. For example, after Fping in footprinting, it may be connected to Nmap Scan or TCPScan in scanning. Completing a composite attack means that abnormal alarms for 5 steps targeting the same destination IP may be detected.

[0089] Even for new attack types, they will go through the previous four attack stages or 5 attack steps. Thus, by detecting abnormal traffic under the attack stages or attack steps, abnormal situations can be effectively identified regardless of the attack type, and security alarms can be issued. Additionally, if the detected abnormal traffic is matched with the learned composite attack graph (the composite attack graph is obtained from alarm data and is also called the alarm graph in the present invention), it is also possible to give a pre-alarm for possible abnormalities in the next step, perform security protection in advance, and improve the alarm efficiency.

[0090] Based on this, the present invention proposes a network traffic detection method. In this method, the tokens included in the abnormal traffic under each network protocol can be summarized and learned, and these tokens are used to detect the abnormal traffic under each network protocol, so that abnormal situations can be effectively identified for new attack types, security alarms can be issued, and according to the detected alarm data, the learned alarm graph can be used to predict possible abnormal traffic in the next step for pre-alarm, perform security protection in advance, and improve the alarm efficiency.

[0091] The following is an example description with reference to the accompanying drawings. Please refer to Figure 2 , Figure 2 which is a schematic flowchart of a network traffic detection method shown in an embodiment of the present invention.

[0092] Figure 2 The shown network traffic detection method can be applied to an electronic device. Among them, the electronic device can execute this method by running software logic corresponding to the network traffic detection method. The type of the electronic device can be a laptop computer, a computer, a server, a mobile phone, a personal digital assistant (PDA), etc. The type of the electronic device is not particularly limited in the present invention. The electronic device can also be a client device or a server device.

[0093] Such as Figure 2As shown, the method may include S202 - S206. Unless otherwise specified, the present invention does not particularly limit the execution order of these steps.

[0094] S202, based on the analysis results of the first network traffic under each network protocol, obtain the tokens of the abnormal traffic of each said network protocol.

[0095] The network protocols include the protocols corresponding to the information collection phase, vulnerability scanning phase, network attack phase, and data stealing phase. In some examples, reference can be made to the protocols shown in Table 1.

[0096] The first network traffic refers to the traffic used to update the token. The first or second is for the convenience of differentiating network traffic.

[0097] In this step, some existing network traffic anomaly detection methods can be used to track and analyze the first network traffic. If abnormal traffic is found, these traffic can be marked. When the abnormal traffic reaches a certain quantity, statistical analysis methods can be used to extract the segments that the abnormal traffic under each network protocol usually has, and form tokens.

[0098] For example, most of the abnormal traffic under the Mysql.Value protocol may contain the segment "k0\efffffal", and this segment is the token corresponding to the Mysql.Value protocol.

[0099] For another example, most of the abnormal traffic under the http.filename protocol may contain the segment "0\eff", and this segment is the token corresponding to the http.filename protocol.

[0100] In this step, corresponding tokens that can identify abnormal traffic can be formed for each protocol.

[0101] S204, use the token to match the second network traffic under each said network protocol. In response to matching the target alarm data under any protocol using the token, mount the target node corresponding to the target alarm data on the alarm graph.

[0102] The second network traffic can be the traffic to be detected.

[0103] The alarm graph is formed based on alarm data. In some embodiments, the alarm data can be some historical alarm data.

[0104] The alarm graph includes at least one alarm data node, and the alarm data nodes are connected in the order of the same source IP, the same destination IP, the same source port, the same destination port, and the sequence of time.

[0105] Taking the alarm data shown in Table 2 as an example.

[0106] Table 2 Example of Alarm Data

[0107]

[0108] Based on the historical alarm data in Table 2, the following can be obtained Figure 9 the alarm graph as shown. Please refer to Figure 9 , Figure 9 which is a schematic diagram of an alarm graph illustrated by the present invention.

[0109] As Figure 9 shown, each node may include information such as alarm time, source IP, destination IP, source port, destination port, attack type, attack step, etc. The attack type can be understood as the network protocol with anomalies. The attack step is the step or stage where anomalies occur. In the present invention, 5 steps are taken as an example.

[0110] The source IP, destination IP, source port, and destination port of Node 1, Node 4, and Node 5 are the same. According to the chronological order, it can be obtained that Node 1 is connected to Node 4 and Node 4 is connected to Node 5. The source IPs of Node 2 and Node 3 are different from those of other nodes, so they are independent nodes respectively, waiting for other nodes with the same source IP that come later to be mounted. The finally shown alarm graph can associate all the historical alarm data. Among them, nodes with the same source IP, destination IP, source port, and destination port can be connected in series according to the chronological order. Nodes with different source IPs do not interfere with each other and each will form a node link.

[0111] It can be understood that each node link can indicate a composite attack. By analyzing the node link, it can be known the target being attacked, that is, the target IP; the attack protocol, that is, the network protocol with anomalies. By sorting the network protocols in chronological order, the connection relationship between the network protocols in the composite attack can also be obtained. For example, through the connection relationship of Node 1, Node 4, and Node 5, it can be obtained that Fping -> tcpcsan -> Arp. When the alarm graph is complete enough, the following can also be obtained Figure 1 the network protocol link as shown. The attack type refers to the network protocol with abnormal traffic, so the network protocol link is the attack type link.

[0112] In S204, after detecting abnormal traffic for any protocol using the token, target alarm data can be generated and the following can be produced Figure 9Target nodes similar to the shown nodes can then find the upstream nodes to be mounted in the graph in the order of the same source IP, the same destination IP, the same source port, the same destination port, and the sequence of time, complete the mounting, and thus can expand the alarm graph in real time. Additionally, the currently detected abnormal traffic can be recorded. Later, by tracing the alarm graph, the attack process of the entire composite attack can be traced back.

[0113] S206. According to the first node link containing the target node in the alarm graph, determine the matching second node link in the alarm graph. The second node link contains a complete network protocol link, and determine whether there is a next node connected to the node with any protocol in the second node link. If there is such a next node, generate a pre-alarm message according to the network protocol corresponding to the next node.

[0114] The first node link refers to the link containing the target node. The nodes included in this link may have the same source IP, destination IP, source port, and destination port, and are arranged in the order of time.

[0115] The second node link refers to the node link containing a complete network protocol link. For example, the second node link may include Figure 1 A complete network protocol link from left to right as shown, such as Fping->TCPScan->ARP->Http->Mysql.

[0116] The first node link refers to the link formed by the currently detected abnormal alarms. It will also have a network protocol link. It is possible that only Fping->TCPScan->ARP is detected currently. By comparing with Figure 1 Each of the shown links, the second node link corresponding to the network protocol link Fping->TCPScan->ARP->Http->Mysql with the highest matching degree can be obtained.

[0117] After finding the second node link, nodes with any protocol can be found. Assume that the protocol of the current alarm is the ARP protocol. Then find the node with the ARP protocol, and then determine whether there is a next node connected to this node. If there is a next node after the second node link, it indicates that an alarm similar to the next node may also occur in the next step. Thus, the source IP, destination IP, source port, and destination port in the alarm data corresponding to the next node can be replaced with the same data corresponding to the nodes in the first node link to generate a pre-alarm. For example, if Http is connected after ARP, the IP, port, etc. information included in the target node can be used to generate a pre-alarm for Http, knowing the risk in advance and facilitating relevant protection.

[0118] Thus, through the solutions corresponding to S202 - S206, on the one hand, it is possible to summarize and learn the tokens included in the abnormal traffic under each network protocol, and use this token to detect the abnormal traffic under each network protocol. Thus, regardless of the type of attack, especially for new types of attacks, it is also possible to effectively identify abnormalities and issue security alerts.

[0119] On the other hand, according to the alarm data, an alarm graph can be formed in the order of the same source IP, the same destination IP, the same source port, the same destination port, and the chronological order. Thus, it is possible to complete the learning of the network protocol link of the composite attack, and it is also possible to record the currently detected abnormal traffic. Later, by tracing the alarm graph, the entire attack process of the composite attack can be traced back.

[0120] On yet another hand, according to the detected alarm data, the learned alarm graph can be used to predict the abnormal traffic that may occur next for pre - warning, perform security protection in advance, and improve the alarm efficiency.

[0121] In some embodiments, an attack graph can be generated based on the alarm graph and presented to the user. The user can intuitively understand information such as the link of various attacks, the attack target, whether the attack is successful, the attack strategy, and the attack tool.

[0122] Please refer to Figure 3 , Figure 3 which is a schematic flowchart of a method for generating an attack graph according to the present invention. As Figure 3 shown, the method may include S302 - S308.

[0123] S302, obtain at least one node link in the alarm graph.

[0124] This step can obtain the node link by accessing the database. In some ways, the node link can be a node link with a complete protocol link.

[0125] S304, for each of the node links, extract the information of each node included in the node link, and the information includes attack protocol information, target IP information, and whether the attack is successful information.

[0126] Each node has fields preset corresponding to various types of information. After matching the target alarm data previously, the fields can be filled according to the target alarm data to form a target node. In some embodiments, the node may include attack protocol information, target IP information, and whether the attack is successful information. Of course, it may also include other required fields.

[0127] In this step, the node information can be obtained through data access.

[0128] S306. Generate an attack graph corresponding to each of the node links based on the extracted information.

[0129] In some ways, the structure of the attack graph, i.e., the included graph nodes, can be preset, and then the corresponding relationship between each graph node and the node field information can be preset.

[0130] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of an attack graph illustrated in the present invention.

[0131] As Figure 4 shown, the attack graph includes an attack target node, an attack tool node, an attack strategy node, an attack effect node, an attack capability node, and an attack event sequence; wherein, the target node includes the target IP information, the attack effect includes the information on whether the attack is successful, the attack tool node includes a set of attack protocol information, and the attack strategy node includes a set of attack protocol information arranged in chronological order; the attack capability node includes a set of business stages corresponding to the attack protocol information, and the attack event sequence includes a set of alarm data nodes arranged in chronological order.

[0132] Then, through the corresponding relationship and using the node information extracted in S304, the construction of the attack graph can be completed.

[0133] In some ways, to more clearly display the attack graph, the attack event sequence can be expanded into the form of attack steps and attack features. Please refer to Figure 5 , Figure 5 which is a schematic structural diagram of an attack graph illustrated in the present invention. Figure 5 In addition to the same structure as Figure 4 , it also includes at least 1 attack step node and at least 1 attack feature extracted from the attack steps. The attack step can be understood as the alarm data arranged in chronological order, and the attack feature can be understood as the alarm information of a preset dimension extracted from the alarm data, i.e., the node information of a preset dimension. For example, network protocol, source IP, attack time, number of attacks, etc.

[0134] S308. Display the attack graph corresponding to each of the node links.

[0135] In this step, in response to the display request, the attack graph generated in S306 can be displayed through a web page. In some ways, Figure 5 the attack step nodes shown in

[0136] Through the solutions described in S302 - S308, an attack graph can be generated based on the alarm graph and presented to the user. The user can intuitively understand information such as the attack link, attack target, whether the attack is successful, attack strategy, and attack tool of various attacks.

[0137] In some embodiments, tokens can be refined in some ways. The refined tokens have a low false alarm rate and a high coverage rate (correct rate).

[0138] Please refer to Figure 6 , Figure 6 , which is a schematic flowchart of a method for obtaining a token according to the present invention. Figure 6 The steps shown are the description of S202. As Figure 6 shown, the method may include S602 - S604.

[0139] S602, for each network protocol, among the traffic determined to be suspicious traffic under the network protocol, the segments with the recurrence times reaching the first threshold are determined as the first tokens.

[0140] This step can refer to the relevant steps, that is, conventional abnormal traffic detection tools can be used to detect abnormal traffic. After detecting the abnormal traffic, for the abnormal traffic under each network protocol, through statistical methods, the segments with the recurrence times reaching the first threshold are sorted out and determined as the first tokens. The first threshold can be set according to experience. For example, 100, 90, 80, etc.

[0141] S604, screen out the second tokens with a false alarm rate lower than the second threshold and / or a coverage rate higher than the third threshold among the first tokens as the tokens of the abnormal traffic of the network protocol; the false alarm rate refers to the probability that the normal traffic containing the first token is misdetected as abnormal traffic; the coverage rate refers to the probability that the abnormal traffic containing the first token is actually detected as abnormal traffic.

[0142] This step is to perform a refined screening on the tokens obtained in S602. The network traffic can be detected using the first tokens, and the detection results are compared with the detection results using conventional abnormal traffic detection tools. Then, according to the comparison results, the false alarm rate and coverage rate of each first token are statistically calculated. The statistical method for the false alarm rate is the normal traffic detected containing the first token divided by all the traffic containing the first token. The statistical method for the coverage rate is the abnormal traffic detected containing the first token divided by all the traffic containing the first token.

[0143] After obtaining the false alarm rate and the coverage rate, the tokens that meet the conditions can be screened out by using a preset second threshold and a third threshold as the second tokens.

[0144] It can be understood that S604 can be a step that is executed multiple times until there are no longer tokens in the first tokens that do not meet the conditions of the false alarm rate and the coverage rate.

[0145] Through the solution described in S602 - S604, tokens with a low false alarm rate and a high coverage rate (correct rate) can be refined, especially improving the alarm accuracy and the accuracy of the entire solution for network traffic anomaly detection.

[0146] It can be understood that among the tokens obtained through S602, their sub - tokens will also be used as the first tokens, which results in too many tokens and some duplicate tokens. For example, if k0\efffffal is recognized as the first token, efffffal will also be recognized as the first token, and efffffal is a sub - token. In some embodiments, after S602, the sub - tokens in the first tokens can be removed; the sub - tokens are partial segments of the first tokens. In this step, some matching algorithms can be set to match the sub - tokens corresponding to each first token, and then these sub - tokens can be deleted. The matching method is to find the tokens that have duplicate characters with themselves, which are the sub - tokens.

[0147] It can be understood that in S204, if any alarms matched by tokens are used as the target alarm data, the data volume will be very large, and these alarms are often similar or identical alarms under the same network protocol. For example, for source IP1 and destination IP2, dozens of similar alarms may be matched under the ARP protocol. Mounting these alarms in the alarm graph will cause data redundancy. Therefore, these similar alarms need to be aggregated to form 1 target alarm data for mounting, which can reduce the data volume of the alarm graph and improve the detection performance and effect.

[0148] Please refer to Figure 7 , Figure 7 which is a schematic flowchart of the method for aggregating alarms of the present invention. Figure 7 The steps shown are the description of S204. As Figure 7 shown, the method may include S702 - S708.

[0149] S702, collect the first alarm data under each of the network protocols matched by the token.

[0150] This step can use conventional character matching methods. For each network protocol, use the corresponding token for matching to find the first alarm data.

[0151] S704, according to the preset alarm removal rules, remove the duplicate alarm data in the first alarm data to obtain the second alarm data.

[0152] In this step, the removal of duplicate alarm data can be performed within the period corresponding to each network protocol. For example, within this period, for data with the same alarm information (such as source IP, destination IP, network protocol), only 1 piece can be retained.

[0153] S706, for each of the network protocols, within the alarm retention duration corresponding to the network protocol, aggregate the second alarm data under the network protocol;

[0154] In this step, within the alarm retention duration corresponding to each network protocol, the first alarm data cached in the memory can be aggregated according to the following logic to obtain the second alarm data:

[0155] Aggregate in the order of the following conditions. If the aggregation is completed according to the condition with a higher precedence, ignore the condition with a lower precedence:

[0156] The network protocol type, source IP, and destination IP are all the same;

[0157] The source IP and destination IP are both the same;

[0158] The destination IP is the same;

[0159] The source IP is the same.

[0160] That is, for any second alarm data, first check whether there is an alarm with the same network protocol type, source IP, and destination IP. If so, merge them preferentially. If not, check whether there is an alarm with the same source IP and destination IP. If so, they can also be merged, and so on. Then, within the alarm retention duration, the second alarm data can be alarmed.

[0161] In some embodiments, the alarm retention duration of each network protocol can be adaptively adjusted, so as to achieve a better aggregation effect and further improve the detection effect. The method includes: counting the number of abnormal traffic under the network protocol within a unit time;

[0162] Query the alarm duration corresponding to the abnormal traffic quantity in the preset alarm retention duration template and determine it as the alarm retention duration corresponding to the network protocol; the alarm retention duration is between the first value and the second value.

[0163] S708, in response to the aggregation duration of the second alarm data under any protocol reaching the alarm retention duration corresponding to the any protocol, determines the aggregated super alarm as the target alarm data under the any protocol matched by the token.

[0164] When the alarm aggregation duration under any protocol reaches the alarm retention duration, the finally aggregated super alarm is used as the target alarm, and steps such as mounting the target node corresponding to the target alarm data as shown in S204 are performed.

[0165] Through S702 - S708, the redundant data volume of the alarm graph is reduced, and the detection performance and effect are improved.

[0166] In some embodiments, the following steps can be referred to for mounting the alarm graph on the target node:

[0167] Obtain the alarm graph;

[0168] Search for the first node in the alarm graph, where the source IP indicated by the first node is the same as the first source IP indicated by the target alarm data;

[0169] If the first node meeting the conditions is not found, determine the target node as an independent node;

[0170] If the first node meeting the conditions is found, search for the second node among the nodes connected to the first node, where the target IP included in the second node is the same as the first target IP indicated by the target alarm data;

[0171] If the second node meeting the conditions is not found, mount the target node on the first node;

[0172] If the second node meeting the conditions is found, search for the third node among the nodes connected to the second node, where the source port included in the third node is the same as the first source port indicated by the target alarm data;

[0173] If the third node meeting the conditions is not found, mount the target node on the second node;

[0174] If the third node meeting the conditions is found, search for the fourth node among the nodes connected to the third node, where the destination port included in the fourth node is the same as the first destination port indicated by the target alarm data;

[0175] If the fourth node meeting the conditions is not found, mount the target node on the third node;

[0176] If the fourth node that meets the conditions is found, and in response to the alarm time of the fourth node being earlier, mount the target node on the fourth node.

[0177] For example, assume there is an alarm graph for understanding the occurrence order and relationships of network events. The nodes of the alarm graph represent different alarms, and the connections between the nodes represent the relationships between them. The specific information of the target alarm (target node) is as follows:

[0178] First source IP: 192.168.1.10; First target IP: 10.0.0.5; First source port: 443; First destination port: 8080; Alarm time: 2023-09-05 10:00:00.

[0179] These target alarm data can be processed according to the following steps: Obtain the alarm graph: Assume the alarm graph has been loaded and is available for query. Find the first node: Find the node with the source IP of 192.168.1.10 in the alarm graph. Assume you find such a node A. Find the second node: Among the nodes connected to node A, find the node with the target IP of 10.0.0.5. Assume you find such a node B. Find the third node: Among the nodes connected to node B, find the node with the source port of 443. Assume you find such a node C. Find the fourth node: Among the nodes connected to node C, find the node with the destination port of 8080. Assume you find such a node D. Mount the target node: Check the alarm time of node D. If the alarm time of D is earlier than the time of the target alarm data 2023-09-05 2023-09-05 10:00:00, then mount the target alarm data to node D.

[0180] In this example: If the nodes found in the alarm graph sequentially match the source IP, target IP, source port, and destination port, and the alarm time condition is met, then the target alarm data will be mounted to the most qualified node (node D in this example). If no next node is found after finding a node, the target node will be mounted to the found node.

[0181] Node mounting can be completed through the above steps.

[0182] In some embodiments, the following steps can be referred to for matching the second node link in S206:

[0183] Obtain the first node link in the alarm graph that contains the target node;

[0184] Determine a second node link with the highest degree of repetition of the indicated network protocol link according to the network protocol link indicated by the first node link; the second node link corresponds to a composite attack scenario; the composite attack scenario includes multiple network protocols.

[0185] For example, a complete second node link may include a network protocol link of any one of the network protocol links from left to right in Figure 1 The network links included in the first node link may only be part of the links shown in Figure 1 Through the network protocol matching method, the second node link with the highest degree of repetition of the network links included in the first node link can be found.

[0186] In some embodiments, in order to improve the accuracy of pre-warning, pre-warning can be performed when it is determined that the detected first node link does have a high repetition with a composite alarm. In this example, the metrics for measuring the degree of repetition with the composite alarm include the detection rate and / or the matching rate.

[0187] The detection rate refers to the proportion of the network protocols actually detected from the initial network protocol to the network protocol corresponding to the target node when the network protocol corresponding to the target node is detected.

[0188] The composite attack scenario can be understood as Figure 1 Any one of the network protocol links from left to right shown. Each composite attack scenario has an initial network protocol and a final network protocol. When calculating the detection rate, the network protocols from the initial network protocol to the network protocol where the target alarm is located in the composite attack scenario can be determined first, and then the network protocols detected in the first node link can be determined, and the proportion of the number of protocols from the initial network protocol to the network protocol where the target alarm is located can be calculated.

[0189] For example, the composite attack scenario is Fping->TCPScan->ARP->Http->Mysql, and the current target alarm is detected at ARP. Then there are 3 protocols in the composite attack scenario from the initial protocol Fping to ARP. Assuming that only TCPScan and ARP are detected in the first node link, the detection rate of the target node is 2 divided by 3, which is 66.7%.

[0190] It can be understood that the higher the detection rate, the higher the degree of repetition of the currently detected alarm with the composite attack scenario.

[0191] The matching rate refers to the proportion of the network protocols detected in all the network protocols included in the composite attack scenario when the network protocol corresponding to the target node is detected.

[0192] The composite attack scenario can be understood as Figure 1Any network protocol link from left to right is shown. The compound attack scenario has an initial network protocol and a final network protocol. When calculating the matching degree, you can first determine each network protocol from the initial network protocol to the final network protocol in the compound attack scenario, and then determine the number of network protocols detected in the first node link together with the network protocol where the target alarm is located, and divide it by the total number of network protocols in the compound attack scenario to get the matching degree.

[0193] For example, the composite attack scenario is Fping->TCPScan->ARP->Http->Mysql, with a total of 5 protocols. The current target alarm is detected by ARP. Assuming that the first node link only detects TCPScan and ARP, 2 protocols, the matching degree of the target node is 2 divided by 5, which is 40%.

[0194] It can be understood that the higher the detection matching degree, the higher the repetition degree between the currently detected alarm and the compound attack scenario.

[0195] After introducing the calculation methods of the detection degree and the matching degree, the following describes how to determine in S206 whether there is a next node to which the node having the arbitrary protocol in the second node link is connected.

[0196] Calculate the detection degree and / or matching degree corresponding to the target node according to the position of the target node on the first node link; the detection degree refers to the proportion of the network protocols actually detected from the initial network protocol to the network protocol corresponding to the target node in the composite attack scenario when the network protocol corresponding to the target node is detected; the matching degree refers to the proportion of the network protocols detected in all the network protocols included in the composite attack scenario when the network protocol corresponding to the target node is detected;

[0197] In response to the detection degree reaching a fourth threshold and / or the matching degree obtaining a fifth threshold, it is determined whether there is a next node connected to the node having the arbitrary protocol in the second node link.

[0198] In this step, it can be determined whether there is a next node only when the detection degree and / or matching degree meet the standards, thereby avoiding false alarms caused by issuing pre-alarms when the current alarm and the composite attack scenario are not highly repetitive, thereby improving the alarm accuracy and further improving the detection effect.

[0199] The invention also provides a network flow detection system.

[0200] See also Figure 8 , Figure 8 FIG. 1 is a schematic diagram of the structure of a network traffic detection system shown in the present invention. Figure 8As shown, the network traffic detection system 800 includes:

[0201] A token acquisition module 810, which obtains tokens for abnormal traffic of each network protocol according to the analysis results of the first network traffic under each network protocol; the network protocols include the protocols corresponding to the information collection stage, vulnerability scanning stage, network attack stage, and data theft stage;

[0202] An abnormal alarm and node mounting module 820, which uses the token to match the second network traffic under each network protocol, and in response to matching the target alarm data under any protocol by using the token, mounts the target node corresponding to the target alarm data on the alarm graph; the alarm graph includes at least one alarm data node, and the alarm data nodes are connected in the order of the same source IP, the same destination IP, the same source port, the same destination port, and the sequence of time;

[0203] A pre-alarm module 830, which determines a second node link that matches in the alarm graph according to the first node link including the target node in the alarm graph, the second node link includes a complete network protocol link, and determines whether there is a next node connected to the node with the arbitrary protocol in the second node link. If there is such a next node, a pre-alarm message is generated according to the network protocol corresponding to the next node.

[0204] In some embodiments, the system 800 further includes an attack graph generation module for:

[0205] Obtaining at least one node link in the alarm graph;

[0206] For each of the node links, extracting the information of each node included in the node link, the information includes attack protocol information, target IP information, and whether the attack is successful information;

[0207] Generating an attack graph corresponding to each of the node links according to the extracted information, the attack graph includes an attack target node, an attack tool node, an attack strategy node, an attack effect node, an attack ability node, and an attack event sequence; wherein, the target node includes the target IP information, the attack effect includes whether the attack is successful information, the attack tool node includes a set of attack protocol information, the attack strategy node includes a set of attack protocol information arranged in chronological order; the attack ability node includes a set of service stages corresponding to the attack protocol information, and the attack event sequence includes a set of alarm data nodes arranged in chronological order;

[0208] Displaying the attack graph corresponding to each of the node links.

[0209] In some embodiments, the token acquisition module 810 further:

[0210] For each network protocol, determine, from the traffic determined to be suspicious traffic under the network protocol, the segments that appear repeatedly a number of times reaching a first threshold as the first tokens;

[0211] Filter out second tokens among the first tokens with a false alarm rate lower than a second threshold and / or a coverage rate higher than a third threshold as the tokens of the abnormal traffic of the network protocol; the false alarm rate refers to the probability that normal traffic containing the first token is misdetected as abnormal traffic; the coverage rate refers to the probability that abnormal traffic containing the first token is indeed detected as abnormal traffic.

[0212] In some embodiments, the token acquisition module 810 further:

[0213] After determining the first tokens, remove the sub-tokens in the first tokens; the sub-tokens are partial segments of the first tokens.

[0214] In some embodiments, the abnormal alarm and node mounting module 820 further:

[0215] Collect the first alarm data under each network protocol matched by the tokens;

[0216] According to a preset alarm removal rule, remove the duplicate alarm data in the first alarm data to obtain second alarm data;

[0217] For each network protocol, aggregate the second alarm data under the network protocol within the alarm retention duration corresponding to the network protocol;

[0218] In response to the aggregation duration of the second alarm data under any protocol reaching the alarm retention duration corresponding to the any protocol, determine the aggregated super alarm as the target alarm data under the any protocol matched by the tokens.

[0219] In some embodiments, the abnormal alarm and node mounting module 820 further:

[0220] Count the number of abnormal traffic under the network protocol per unit time;

[0221] Query, in a preset alarm retention duration template, the alarm duration corresponding to the number of abnormal traffic and determine it as the alarm retention duration corresponding to the network protocol; the alarm retention duration is between a first value and a second value.

[0222] In some embodiments, the anomaly alert and node mounting module 820 further:

[0223] Aggregate in the order of the following conditions. If the aggregation is completed according to the condition with a higher precedence in sorting, ignore the conditions with lower precedence in sorting:

[0224] The network protocol type, source IP, and destination IP are all the same;

[0225] The source IP and destination IP are both the same;

[0226] The destination IP is the same;

[0227] The source IP is the same.

[0228] In some embodiments, the anomaly alert and node mounting module 820 further:

[0229] Obtain an alert graph;

[0230] Search for a first node in the alert graph, where the source IP indicated by the first node is the same as the first source IP indicated by the target alert data;

[0231] If the first node that meets the condition is not found, determine the target node as an independent node;

[0232] If the first node that meets the condition is found, search for a second node among the nodes connected to the first node, where the target IP included in the second node is the same as the first target IP indicated by the target alert data;

[0233] If the second node that meets the condition is not found, mount the target node on the first node;

[0234] If the second node that meets the condition is found, search for a third node among the nodes connected to the second node, where the source port included in the third node is the same as the first source port indicated by the target alert data;

[0235] If the third node that meets the condition is not found, mount the target node on the second node;

[0236] If the third node that meets the condition is found, search for a fourth node among the nodes connected to the third node, where the destination port included in the fourth node is the same as the first destination port indicated by the target alert data;

[0237] If the fourth node that meets the condition is not found, mount the target node on the third node;

[0238] If the fourth node that meets the conditions is found, and in response to the alarm time of the fourth node being earlier, mount the target node to the fourth node.

[0239] In some embodiments, the pre-alarm module 830 further:

[0240] Obtain a first node link in the alarm graph that includes the target node;

[0241] According to the network protocol link indicated by the first node link, determine a second node link with the highest degree of repetition of the indicated network protocol link; the second node link corresponds to a composite attack scenario; the composite attack scenario includes multiple network protocols;

[0242] The determining whether there is a connected next node for a node with any protocol in the second node link includes:

[0243] According to the position of the target node in the first node link, calculate the detection degree and / or matching degree corresponding to the target node; the detection degree refers to the proportion of the network protocols actually detected from the initial network protocol to the network protocol corresponding to the target node in the composite attack scenario when the network protocol corresponding to the target node is detected; the matching degree refers to the proportion of the network protocols detected among all the network protocols included in the composite attack scenario when the network protocol corresponding to the target node is detected;

[0244] In response to the detection degree reaching a fourth threshold and / or the matching degree reaching a fifth threshold, determine whether there is a connected next node for a node with any protocol in the second node link.

[0245] In any of the above embodiments, on the one hand, it is possible to summarize and learn the tokens included in the abnormal traffic under each network protocol, and use the tokens to detect the abnormal traffic under each network protocol, so that regardless of the type of attack, especially for new types of attacks, it is also possible to effectively identify abnormalities and issue security alarms.

[0246] On the other hand, according to the alarm data, an alarm graph can be formed in the order of the same source IP, the same destination IP, the same source port, the same destination port, and the sequence of time, so that it is possible to complete the learning of the network protocol link of the composite attack, and it is also possible to record the currently detected abnormal traffic. Later, by tracing the alarm graph, the entire attack process of the composite attack can be traced back.

[0247] On the other hand, according to the detected alarm data, the learned alarm graph can be used to predict the abnormal traffic that may occur next for pre-alarm, perform security protection in advance, and improve the alarm efficiency.

[0248] In the method of the present invention, the tokens included in the abnormal traffic under each network protocol can be summarized and learned, and the tokens can be used to detect the abnormal traffic under each network protocol, so that for new attack types, abnormal situations can also be effectively identified for security alerts. Moreover, based on the detected alert data, the learned alert graph can be used to predict the abnormal traffic that may occur next for pre-alerting, and security protection can be carried out in advance to improve the alert efficiency.

[0249] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principles of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. A network traffic detection method, characterized in that: The method comprises: According to the analysis results of the first network traffic under each network protocol, a token of the abnormal traffic of each network protocol is obtained; the network protocol includes: protocols corresponding to the information collection stage, the vulnerability scanning stage, the network attack stage and the data theft stage; The token is used to match the second network traffic under each of the network protocols, and in response to the target alarm data under any protocol being matched by the token, the target node corresponding to the target alarm data is mounted on the alarm map; the alarm map includes at least one alarm data node, and the alarm data nodes are connected in the order of the same source IP, the same destination IP, the same source port, the same destination port, and the time sequence; According to the first node link containing the target node in the alarm map, a matching second node link in the alarm map is determined, wherein the second node link contains a complete network protocol link, and it is determined whether there is a next node connected to the node with any protocol in the second node link. If the next node exists, a pre-alarm message is generated according to the network protocol corresponding to the next node.

2. The network traffic detection method according to claim 1, characterized in that: The method further comprises: Obtain at least one node link in the alarm graph; For each of the node links, extract information of each node included in the node link, the information including attack protocol information, target IP information and information on whether the attack is successful; An attack graph corresponding to each of the node links is generated according to the extracted information, wherein the attack graph includes: an attack target node, an attack tool node, an attack strategy node, an attack effect node, an attack capability node, and an attack event sequence; wherein the attack target node includes the target IP information, the attack effect node includes information on whether the attack is successful, the attack tool node includes a set of attack protocol information, the attack strategy node includes a set of attack protocol information arranged in chronological order; the attack capability node includes a set of business stages corresponding to the attack protocol information, and the attack event sequence includes a set of alarm data nodes arranged in chronological order; The attack graph corresponding to each of the node links is displayed.

3. The network traffic detection method according to claim 1, characterized in that: The step of obtaining the token of abnormal traffic of each network protocol according to the analysis result of the first network traffic under each network protocol includes: For each network protocol, a segment whose number of repetitions reaches a first threshold in traffic determined as suspicious traffic under the network protocol is determined as a first token; Filter out the second token in the first token whose false alarm rate is lower than the second threshold and / or whose coverage rate is higher than the third threshold as the token of the abnormal traffic of the network protocol; the false alarm rate refers to the probability that the normal traffic containing the first token is mistakenly detected as abnormal traffic; the coverage rate refers to the probability that the abnormal traffic containing the first token is indeed detected as abnormal traffic.

4. The network traffic detection method according to claim 3, characterized in that: After determining the first token, it also includes: Remove the sub-token in the first token; the sub-token is a partial fragment of the first token.

5. The network traffic detection method according to claim 1, characterized in that: The using the token to match the second network traffic under each of the network protocols includes: Collecting the first alarm data under each of the network protocols matched by using the token; According to a preset alarm removal rule, duplicate alarm data in the first alarm data is removed to obtain second alarm data; For each of the network protocols, aggregating the second alarm data under the network protocol within the alarm retention time corresponding to the network protocol; In response to the aggregation duration of the second alarm data under any protocol reaching the alarm retention duration corresponding to the arbitrary protocol, the super alarm obtained by aggregation is determined as the target alarm data under the arbitrary protocol matched by using the token.

6. The network traffic detection method according to claim 5, characterized in that: The aggregating the second alarm data under the network protocol includes: Aggregate in the following order. If the aggregation is completed according to the conditions that come first, the conditions that come later are ignored: The network protocol type, source IP, and destination IP are the same; The source IP and destination IP are the same; The destination IP is the same; The source IP is the same.

7. The network traffic detection method according to claim 1, characterized in that: The step of mounting the target node corresponding to the target alarm data on the alarm map includes: Get the alarm map; Searching for a first node in the alarm graph, wherein the source IP indicated by the first node is the same as the first source IP indicated by the target alarm data; If the first node that meets the condition is not found, determining the target node as an independent node; If the first node that meets the condition is found, a second node is searched among the nodes connected to the first node, and the target IP included in the second node is the same as the first target IP indicated by the target alarm data; If the second node that meets the condition is not found, mounting the target node on the first node; If the second node that meets the condition is found, searching for a third node among the nodes connected to the second node, wherein the source port included in the third node is the same as the first source port indicated by the target alarm data; If the third node that meets the condition is not found, mounting the target node on the second node; If the third node that meets the condition is found, searching for a fourth node among the nodes connected to the third node, wherein the destination port included in the fourth node is the same as the first destination port indicated by the target alarm data; If the fourth node that meets the condition is not found, mounting the target node on the third node; If the fourth node that meets the conditions is found, in response to the fourth node having an earlier alarm time, the target node is mounted on the fourth node.

8. The network traffic detection method according to claim 1, characterized in that: The determining, according to the first node link containing the target node in the alarm graph, a second node link matching in the alarm graph comprises: Acquire a first node link including the target node in the alarm graph; According to the network protocol link indicated by the first node link, determining a second node link with the highest indicated network protocol link repetition; the second node link corresponds to a composite attack scenario; the composite attack scenario includes multiple network protocols; The determining whether there is a next node connected to the node with the arbitrary protocol in the second node link comprises: Calculate the detection degree and / or matching degree corresponding to the target node according to the position of the target node on the first node link; the detection degree refers to the proportion of the network protocols actually detected from the initial network protocol to the network protocol corresponding to the target node in the composite attack scenario when the network protocol corresponding to the target node is detected; the matching degree refers to the proportion of the network protocols detected in all the network protocols included in the composite attack scenario when the network protocol corresponding to the target node is detected; In response to the detection degree reaching a fourth threshold and / or the matching degree obtaining a fifth threshold, it is determined whether there is a next node connected to the node having the arbitrary protocol in the second node link.

9. A network traffic detection system, characterized in that: The system comprises: A token acquisition module, which obtains the token of the abnormal traffic of each network protocol according to the analysis result of the first network traffic under each network protocol; the network protocol includes protocols corresponding to the information collection stage, vulnerability scanning stage, network attack stage and data theft stage; The abnormal alarm and node mounting module uses the token to match the second network traffic under each of the network protocols, and in response to matching the target alarm data under any protocol using the token, mounts the target node corresponding to the target alarm data on the alarm map; the alarm map includes at least one alarm data node, and the alarm data nodes are connected in the order of the same source IP, the same destination IP, the same source port, the same destination port, and the time sequence; The pre-alarm module determines a matching second node link in the alarm map based on a first node link containing the target node in the alarm map, wherein the second node link contains a complete network protocol link, and determines whether there is a next node connected to a node with any protocol in the second node link. If the next node exists, pre-alarm information is generated based on the network protocol corresponding to the next node.

Citation Information

Patent Citations

  • Network attack path tracking method and device

    CN113783896A

  • Security event collaborative monitoring and early warning method, system and equipment and medium

    CN116668054A