Network security protection method, device and electronic equipment
By combining the white traffic model, WAF detection engine and feature detection model, and using a combination of machine learning and manual analysis to adjust the parameters of the WAF feature library and white traffic model, the shortcomings of existing technologies in identifying and responding to new network attacks are resolved, achieving higher detection accuracy and adaptability.
CN119449417BActive Publication Date: 2025-09-26CHINA TELECOM NETWORK SECURITY TECH CO LTD
2 Cites 0 Cited by
Patent Information
- Application Number
- CN202411578479.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-06
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2044-11-06
AI Technical Summary
Technical Problem
Existing network security protection technologies are unable to effectively identify and respond to new network attacks and variant attacks, resulting in insufficient detection accuracy and adaptability.
Method used
By combining the white traffic model and WAF detection engine with the feature detection model, and combining machine learning with manual analysis, the parameters of the WAF feature library and white traffic model are adjusted to identify network attack characteristics and enhance defense capabilities.
Benefits of technology
It improves the accuracy and adaptability of network attack detection, can effectively respond to new and variant attacks, and enhances the adaptability and defense capabilities of network security protection.
✦ Generated by Eureka AI based on patent content.
Abstract
The present application relates to the field of network security technology, and in particular to a network security protection method, device and electronic device. The method includes obtaining traffic data to be detected. The traffic data to be detected is input into a white traffic model to obtain a first detection result. The traffic data to be detected is input into a network application firewall (WAF) detection engine to obtain a second detection result. If the first detection result is different from the second detection result, a feature detection model is used to extract traffic features related to the traffic to be detected and the network attack. Among them, the feature detection model is a machine learning model for analyzing network traffic and extracting traffic features related to network attacks. The traffic features and the attack payload of the traffic data to be detected are transmitted to the cloud for manual analysis and judgment, and the model parameters of the WAF feature library or the white traffic model are adjusted based on the manual analysis and judgment results. The above scheme can achieve network security protection and protect computer system and data security.
Need to check novelty before this filing date? Find Prior Art