Network security protection method, device and electronic equipment

By combining the white traffic model, WAF detection engine and feature detection model, and using a combination of machine learning and manual analysis to adjust the parameters of the WAF feature library and white traffic model, the shortcomings of existing technologies in identifying and responding to new network attacks are resolved, achieving higher detection accuracy and adaptability.

CN119449417BActive Publication Date: 2025-09-26CHINA TELECOM NETWORK SECURITY TECH CO LTD
2 Cites 0 Cited by

Patent Information

Application Number
CN202411578479.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-06
Publication Date
2025-09-26
Estimated Expiration
2044-11-06

AI Technical Summary

Technical Problem

Existing network security protection technologies are unable to effectively identify and respond to new network attacks and variant attacks, resulting in insufficient detection accuracy and adaptability.

Method used

By combining the white traffic model and WAF detection engine with the feature detection model, and combining machine learning with manual analysis, the parameters of the WAF feature library and white traffic model are adjusted to identify network attack characteristics and enhance defense capabilities.

Benefits of technology

It improves the accuracy and adaptability of network attack detection, can effectively respond to new and variant attacks, and enhances the adaptability and defense capabilities of network security protection.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The present application relates to the field of network security technology, and in particular to a network security protection method, device and electronic device. The method includes obtaining traffic data to be detected. The traffic data to be detected is input into a white traffic model to obtain a first detection result. The traffic data to be detected is input into a network application firewall (WAF) detection engine to obtain a second detection result. If the first detection result is different from the second detection result, a feature detection model is used to extract traffic features related to the traffic to be detected and the network attack. Among them, the feature detection model is a machine learning model for analyzing network traffic and extracting traffic features related to network attacks. The traffic features and the attack payload of the traffic data to be detected are transmitted to the cloud for manual analysis and judgment, and the model parameters of the WAF feature library or the white traffic model are adjusted based on the manual analysis and judgment results. The above scheme can achieve network security protection and protect computer system and data security.
Need to check novelty before this filing date? Find Prior Art