A method, device, terminal and medium for analyzing abnormal communication traffic

Through the construction of program types and layered monitoring architecture, abnormal programs are identified and analyzed, the problem of abnormal communication traffic identification is solved, the security and stability of the terminal is improved, and business interruptions are reduced.

CN119544287BActive Publication Date: 2025-05-30CHINA MERCHANTS IND DIGITAL TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411648400.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-05-30
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

How to identify the target address of abnormal programs and their communication traffic, and solve problems such as network attacks, configuration errors and hardware failures caused by abnormal communication traffic.

Method used

Through program types division, the construction of hierarchical monitoring architecture, the monitoring of abnormal programs and the creation of redundant versions, the abnormal programs are gradually determined and analyzed, the target address of the communication traffic is located, and an analysis report is generated.

Benefits of technology

It improves the screening and analysis efficiency of abnormal programs, enhances the security and stability of user terminals, reduces business interruptions, ensures the continuous availability of terminals, and improves fault diagnosis capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119544287B_ABST
    Figure CN119544287B_ABST
Patent Text Reader

Abstract

The present invention relates to a method, device, terminal and medium for analyzing abnormal communication traffic. The method for analyzing abnormal communication traffic includes classifying programs in a user terminal, configuring priorities; constructing a hierarchical monitoring architecture, when it is monitored that the communication traffic of the user terminal exceeds a threshold, migrating all types to the basic layer for traffic restriction, unlocking types according to priorities; hanging an abnormal program under the monitoring layer, creating a redundant version, and synchronizing basic data in the abnormal program; locating the target address of the communication traffic exceeding the threshold, generating an access control list by applying the redundant version, comparing it with the target address to obtain abnormal items; integrating and sending information. The present invention reduces service interruption and ensures the continuous availability of the user terminal by creating a redundant version, and improves the fault diagnosis ability by comparing the target address and the access control list, providing decision support for the persistent and stable operation of the user terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of anomaly analysis, and particularly to a method, device, terminal and medium for analyzing communication traffic anomalies. Background Art

[0002] Communication traffic refers to the amount of data transmitted in a network, usually measured in data packets, bits or bytes, which reflects the flow of data in the network. Communication traffic includes all information transmitted from one device to another. By continuously collecting communication traffic, such as the size of data packets, traffic rate and number of connections, and using algorithms such as machine learning to find anomalies, such as sudden increases in traffic, abnormal connection patterns or abnormal traffic distributions, the stable and persistent operation of the terminal can be ensured. Communication traffic anomalies may be caused by network attacks, configuration errors and hardware failures, etc.

[0003] Therefore, "how to identify abnormal programs and the target addresses of their communication traffic" is the technical problem to be solved by the present invention. Summary of the Invention

[0004] The purpose of the present invention is to provide a method, device, terminal and medium for analyzing communication traffic anomalies to solve the problem of "how to identify abnormal programs and the target addresses of their communication traffic" proposed in the above background art.

[0005] To achieve the above purpose, the present invention provides the following technical solutions:

[0006] A method for analyzing communication traffic anomalies, the method comprising:

[0007] S100: Program type classification, classifying the programs in the user terminal into several types, the types at least including social, storage and office, and configuring a priority for each type;

[0008] S200: Abnormal program confirmation, constructing a hierarchical monitoring architecture, wherein the hierarchical monitoring architecture includes a basic layer and a monitoring layer. When the communication traffic of the user terminal is detected to exceed the threshold, all the types are migrated to the basic layer and traffic restriction is performed. In the order of decreasing priority, the types are unlocked in turn, the types with abnormal communication traffic are traversed to determine the abnormal types, and traffic restriction is continued for the programs in the abnormal types and unlocked in turn to find the abnormal programs;

[0009] S300: Abnormal program monitoring, hanging the abnormal program under the monitoring layer, creating a redundant version, synchronizing the basic data in the abnormal program to the redundant version, and integrating a pre-constructed complete monitoring mechanism into the hierarchical monitoring architecture;

[0010] S400: Abnormal item confirmation. Through the monitoring mechanism, when the communication traffic of the abnormal program is detected to exceed the threshold, locate the target address of the communication traffic, trigger the start of the redundant version, generate an access control list, compare the target address with the access control list, and define the abnormal item;

[0011] S500: Information integration and sending. Integrate the abnormal program and the abnormal item, generate an analysis report, and send the analysis report to a preset terminal.

[0012] Furthermore, the S100 includes:

[0013] Determine the usage frequency of each program, and dynamically adjust the priority based on the usage frequency.

[0014] Furthermore, the S200 includes:

[0015] Create a multi-level restriction mechanism and transfer it to the hierarchical monitoring architecture, where the multi-level restriction mechanism is: when the communication traffic of the user terminal is detected to exceed the threshold, determine whether the user is using the program. If so, delete the program being used from the category;

[0016] Mark the root node in the basic layer, transfer the program being used to the root node, build a data transmission channel for the root node, and issue the usage permission of the data transmission channel to the program being used.

[0017] Furthermore, the S200 also includes:

[0018] Allocate traffic quotas for each category based on the traffic restriction;

[0019] Determine the remaining traffic of each category and summarize it to generate a shared traffic pool.

[0020] Furthermore, the S300 includes:

[0021] Create several redundant versions, collect the tasks in the abnormal program, and use the redundant versions to process the tasks in parallel;

[0022] Split the abnormal program into basic data and configuration data, and synchronize the basic data to the redundant versions.

[0023] Furthermore, the S400 includes:

[0024] Record the receiving address of the communication traffic in the abnormal program and define it as the target address;

[0025] In the utilization of redundant versions, draw an access control list based on the receiving addresses of communication traffic, compare the differences between the target addresses and the access control list, and define the differences as exception items.

[0026] Furthermore, the device includes:

[0027] A configuration module, used to divide the programs in the user terminal into several categories, where the categories at least include: social, storage, and office, and configure priorities for each of the categories;

[0028] A search module, used to construct a hierarchical monitoring architecture, where the hierarchical monitoring architecture includes: a basic layer and a monitoring layer. When it is detected that the communication traffic of the user terminal exceeds the threshold, migrate all the categories to the basic layer, perform traffic restriction, and unlock the categories in order from the highest to the lowest priority, traverse the categories with abnormal communication traffic to obtain abnormal categories, continue to perform traffic restriction on the programs in the abnormal categories, and unlock them in sequence to find abnormal programs;

[0029] An integration module, used to hang the abnormal programs under the monitoring layer, create redundant versions, synchronize the basic data in the abnormal programs to the redundant versions, and integrate a pre-constructed monitoring mechanism into the hierarchical monitoring architecture;

[0030] A sending module, used via the monitoring mechanism. When it is detected that the communication traffic of the abnormal programs exceeds the threshold, locate the target addresses of the communication traffic, trigger the start of the redundant versions, generate an access control list, compare the target addresses with the access control list, define exception items, integrate the abnormal programs and the exception items, generate an analysis report, and send the analysis report to a preset terminal.

[0031] Furthermore, the configuration module includes:

[0032] An adjustment unit, used to determine the usage frequency of each program, and dynamically adjust the priorities based on the usage frequency.

[0033] Furthermore, a terminal, the terminal includes one or more processors and one or more memories, and at least one program code is stored in the one or more memories, and the program code is loaded and executed by the one or more processors.

[0034] Furthermore, a medium, at least one program code is stored in the medium, and the program code is loaded and executed by a processor.

[0035] Compared with the prior art, the beneficial effects of the present invention are:

[0036] Through classification by type and using the recursive idea, the process of determining abnormal programs is greatly simplified, the screening and analysis efficiency of abnormal programs is improved. By constructing a hierarchical monitoring architecture, detailed analysis of abnormal programs can be carried out within the isolation area, avoiding affecting the normal operation of the user terminal, and at the same time greatly improving the security and stability of the user terminal. By creating redundant versions, business interruptions can be reduced and the continuous availability of the user terminal can be ensured. By comparing the target address with the access control list, abnormal communication traffic of the user terminal can be identified, and the fault diagnosis ability can be improved, thereby providing decision support for the persistent and stable operation of the user terminal. Description of the Drawings

[0037] Figure 1 It is a flowchart of the communication traffic anomaly analysis method provided by an embodiment of the present invention;

[0038] Figure 2 It is the second sub-flowchart of the communication traffic anomaly analysis method provided by an embodiment of the present invention;

[0039] Figure 3 It is the third sub-flowchart of the communication traffic anomaly analysis method provided by an embodiment of the present invention;

[0040] Figure 4 It is the fourth sub-flowchart of the communication traffic anomaly analysis method provided by an embodiment of the present invention;

[0041] Figure 5 It is a block diagram of the composition of the communication traffic anomaly analysis device provided by an embodiment of the present invention;

[0042] Figure 6 It is a block diagram of the composition of the configuration module in the communication traffic anomaly analysis device provided by an embodiment of the present invention;

[0043] Figure 7 It is a block diagram of the composition of the search module in the communication traffic anomaly analysis device provided by an embodiment of the present invention;

[0044] Figure 8 It is a block diagram of the composition of the integration module in the communication traffic anomaly analysis device provided by an embodiment of the present invention;

[0045] Figure 9 It is a block diagram of the composition of the sending module in the communication traffic anomaly analysis device provided by an embodiment of the present invention. Detailed Embodiments

[0046] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0047] In Embodiment 1,Figure 1 The implementation process of a communication traffic anomaly analysis method provided by an embodiment of the present invention is shown, and the details are as follows:

[0048] S100: Program type classification. Programs in the user terminal are classified into several types, which at least include social, storage, and office. A priority is configured for each type.

[0049] Classify the programs in the user terminal to determine multiple types, such as social programs, storage programs, or office programs. At the same time, determine the priority of each type. The priority of each type includes the priority between types and the priority between programs in the same type.

[0050] S200: Abnormal program confirmation. Build a hierarchical monitoring architecture, where the hierarchical monitoring architecture includes a basic layer and a monitoring layer. When it is detected that the communication traffic of the user terminal exceeds a pre-set threshold, all types are migrated to the basic layer, and traffic restriction is performed. According to the priority of each type from high to low, unlock the types in turn, traverse the types with abnormal communication traffic, determine the abnormal types, continue to perform traffic restriction on the programs in the abnormal types, and unlock them in turn to find the abnormal programs.

[0051] The hierarchical monitoring architecture consists of two independent levels, namely the basic layer and the monitoring layer. The basic layer is mainly used to find abnormal programs, while the monitoring layer is mainly used to determine the abnormal receiving location of abnormal communication traffic.

[0052] When it is detected that the communication traffic of the user terminal exceeds the threshold, all types are migrated to the basic layer, and traffic restriction is performed on the programs in all types. Traffic restriction means prohibiting network connection. Then, according to the order of priority from high to low, unlock the programs in each type in turn, find the types with abnormal communication traffic, obtain the abnormal types, and continue to perform traffic restriction on all the programs in the abnormal types according to this method, and unlock them in turn to find the programs with abnormal communication traffic and determine them as abnormal programs.

[0053] S300: Abnormal program monitoring. Hang the abnormal program under the monitoring layer, create a redundant version, synchronize the basic data in the abnormal program to the redundant version, and integrate a pre-built complete monitoring mechanism into the hierarchical monitoring architecture.

[0054] Transfer the abnormal program to the monitoring layer, and at the same time synchronize the basic data in the abnormal program to the redundant version and run the redundant version. Transfer the monitoring mechanism to the hierarchical monitoring architecture, where the monitoring mechanism is the specific monitoring method for the communication traffic of the abnormal program.

[0055] S400: Abnormal item confirmation. Through the monitoring mechanism, when the communication traffic of an abnormal program exceeds the threshold, locate the target address of the communication traffic, trigger the startup of the redundant version, generate an access control list, compare the target address with the access control list, and define the abnormal item.

[0056] If it is detected that the communication traffic of an abnormal program exceeds the threshold, find out the receiving address of the communication traffic of the abnormal program, integrate all the receiving addresses to obtain the target address; start the redundant version, use the receiving addresses of the communication traffic of the redundant version to form an access control list, compare the target address with the access control list, and determine the abnormal item.

[0057] S500: Information integration and sending. Integrate the abnormal program and the abnormal item, generate an analysis report, and send the analysis report to a preset terminal.

[0058] Integrate the abnormal program and the abnormal item into a pre-constructed template to generate an analysis report, and send the analysis report to a preset terminal; where the template can be pre-determined by professionals, and the terminal can be a user terminal (such as: the user's mobile phone, laptop, ipad, etc.) or other specified terminals.

[0059] In Embodiment 2, the implementation process of the communication traffic abnormal analysis method provided by the embodiments of the present invention is proposed. The following details S100 as follows:

[0060] S101: Determine the usage frequency of each program, and dynamically adjust the corresponding priority based on the usage frequency. The specific process of dynamically adjusting the corresponding priority can be: determine the usage frequency of each program, and the higher the usage frequency of the program, the higher the corresponding type of priority will be adjusted.

[0061] In Embodiment 3, Figure 2 The implementation process of the communication traffic abnormal analysis method provided by the embodiments of the present invention is shown. The following details S200, and S200 includes the following steps:

[0062] S201: At the basic layer, arrange the corresponding types in the order of priority. This step can also be executed in S100.

[0063] In the basic layer, arrange all types in descending order of priority.

[0064] S202: Create a multi-level restriction mechanism and transfer it to the hierarchical monitoring architecture, where the multi-level restriction mechanism is: when it is detected that the communication traffic of the user terminal exceeds the pre-set threshold, determine whether the user is using a program. If so, delete the program being used from the type.

[0065] Create a multi-level restriction mechanism. The multi-level restriction mechanism means that when a certain program is in use, traffic restriction is not performed, but it is transferred to the root node for operation. After the program finishes running, traffic restriction is imposed on the program.

[0066] S203: Mark the root node in the basic layer, transfer the program in use to the root node, build the data transmission channel of the root node, and issue the usage permission of the data transmission channel to the program in use.

[0067] Mark the root node in the basic layer. The root node is similar to a "sandbox", which is a computer simulation environment that can isolate and run abnormal programs. The data transmission channel is used for data transmission of abnormal programs.

[0068] In Embodiment 4, Figure 3 The implementation process of the communication traffic anomaly analysis method provided by the embodiment of the present invention is shown. The following details S200 in detail as follows:

[0069] S204: Based on traffic restriction, allocate traffic quotas for each category.

[0070] Set traffic quotas for each program to avoid the phenomenon of "traffic stealing".

[0071] S205: Determine the remaining traffic of each category, summarize it, and generate a shared traffic pool.

[0072] When the traffic quota of a certain program is exhausted, continue to use the traffic in the shared traffic pool. If the shared traffic pool is also exhausted, an alarm message is pushed to the user.

[0073] In Embodiment 5, Figure 3 The implementation process of the communication traffic anomaly analysis method provided by the embodiment of the present invention is shown. The following details S300 in detail as follows:

[0074] S301: Create several redundant versions, collect the tasks in the abnormal program, and use the redundant versions to process the tasks in parallel.

[0075] Create several redundant versions, determine the tasks that need to be executed in the abnormal program, and use the redundant versions to jointly process the tasks. The advantage of doing this is that it can greatly improve the task execution efficiency.

[0076] S302: Split the abnormal program into basic data and configuration data, and synchronize the basic data to the redundant versions.

[0077] The abnormal programs are divided into basic data and configuration data, and the basic data in the abnormal programs is synchronized to the redundant version, so as to ensure the normal execution of tasks and avoid execution anomalies. The basic data can be the environmental data and running status data of the abnormal programs, and the similarity of the basic data of different abnormal programs is relatively high; while the configuration data can be user configuration data, network, security data, etc., and the similarity of the configuration data of different abnormal programs is relatively low.

[0078] In Embodiment 6, Figure 4 The implementation process of the communication traffic anomaly analysis method provided by the embodiment of the present invention is shown. The following details S400 as follows:

[0079] S401: Record the receiving address of the communication traffic in the abnormal program and define it as the target address.

[0080] After determining the abnormal program, locate the receiving address of the communication traffic in the abnormal program and determine this receiving address as the target address.

[0081] S402: Use the receiving address of the communication traffic in the redundant version to draw an access control table, compare the difference between the target address and the access control table, and define this difference as an abnormal item.

[0082] Determine the receiving address of the communication traffic in the redundant version, integrate all the receiving addresses, draw an access control table, compare the difference between the target address and the access control table, and determine the difference as an abnormal item. The abnormal item is the receiving address of the abnormal communication.

[0083] Figure 5 The composition structure block diagram of the communication traffic anomaly analysis device provided by the embodiment of the present invention is shown. The communication traffic anomaly analysis device 1 includes:

[0084] The configuration module 11 is used to divide the programs in the user terminal into several categories, and the categories at least include: social, storage, and office, and configure priorities for each category;

[0085] The search module 12 is used to construct a hierarchical monitoring architecture. The hierarchical monitoring architecture includes a basic layer and a monitoring layer. When it is detected that the communication traffic of the user terminal exceeds the threshold, all categories are migrated to the basic layer, and traffic restriction is performed. According to the order of priorities from high to low, the categories are unlocked in turn, the categories with abnormal communication traffic are traversed to obtain the abnormal categories, and traffic restriction is continued for the programs in the abnormal categories and unlocked in turn to find the abnormal programs;

[0086] The integration module 13 is used to hang the abnormal program under the monitoring layer, create a redundant version, synchronize the basic data in the abnormal program to the redundant version, and integrate the pre-constructed monitoring mechanism into the hierarchical monitoring architecture;

[0087] A sending module 14, which is used to, via a monitoring mechanism, when it monitors that the communication traffic of an abnormal program exceeds a threshold, locate the target address of the communication traffic, trigger the start of a redundant version, generate an access control list, compare the target address with the access control list, define abnormal items, integrate the abnormal program and the abnormal items, generate an analysis report, and send the analysis report to a preset terminal.

[0088] Figure 6 The block diagram of the composition structure of the configuration module 11 in the communication traffic anomaly analysis device provided by an embodiment of the present invention is shown. The configuration module 11 includes:

[0089] An adjustment unit 111, which is used to determine the usage frequency of each program and dynamically adjust the corresponding priority based on the usage frequency.

[0090] Figure 7 The block diagram of the composition structure of the search module 12 in the communication traffic anomaly analysis device provided by an embodiment of the present invention is shown. The search module 12 includes:

[0091] An arrangement unit 125, which is used to arrange types in sequence at the basic layer;

[0092] A judgment unit 121, which is used to create a multi-level restriction mechanism and transfer it to a hierarchical monitoring architecture, where the multi-level restriction mechanism is: when it monitors that the communication traffic of a user terminal exceeds a threshold, judge whether the user is using the program. If so, delete the program being used from the types;

[0093] A distribution unit 122, which is used to mark the root node in the basic layer, transfer the program being used to the root node, build a data transmission channel for the root node, and distribute the usage permission of the data transmission channel to the program being used;

[0094] An allocation unit 123, which is used to allocate a traffic quota for each type according to the traffic limit;

[0095] A generation unit 124, which is used to determine the remaining traffic of each type, summarize it, and generate a shared traffic pool.

[0096] Figure 8 The block diagram of the composition structure of the integration module 13 in the communication traffic anomaly analysis device provided by an embodiment of the present invention is shown. The integration module 13 includes:

[0097] A parallel processing unit 131, which is used to create several redundant versions, collect tasks in the abnormal program, and use the redundant versions to process the tasks in parallel;

[0098] A synchronization unit 132, which is used to split the abnormal program into basic data and configuration data, and synchronize the basic data to the redundant versions.

[0099] Figure 9 The block diagram of the composition of the sending module 14 in the communication traffic anomaly analysis device provided by the embodiment of the present invention is shown. The sending module 14 includes:

[0100] A definition unit 141, configured to record the receiving address of the communication traffic in the abnormal program and define it as the target address;

[0101] A comparison unit 142, configured to draw an access control table using the receiving address of the communication traffic in the redundant version, compare the difference between the target address and the access control table, and define the difference as an abnormal item.

[0102] Among them, the configuration module 11 is mainly used to complete step S100, the search module 12 is mainly used to complete step S200, the integration module 13 is mainly used to complete step S300, and the sending module 14 is mainly used to complete step S400;

[0103] An adjustment unit 111 is mainly used to complete step S101;

[0104] An arrangement unit 125 is mainly used to complete step S201, a judgment unit 121 is mainly used to complete step S202, a sending unit 122 is mainly used to complete step S203, a distribution unit 123 is mainly used to complete step S204, and a generation unit 124 is mainly used to complete step S205;

[0105] A parallel processing unit 131 is mainly used to complete step S301, and a synchronization unit 132 is mainly used to complete step S302;

[0106] The definition unit 141 is mainly used to complete step S401, and the arrangement unit 142 is mainly used to complete step S402.

[0107] A terminal provided by an embodiment of the present invention includes one or more processors and one or more memories. At least one program code is stored in the one or more memories, and the program code is loaded and executed by the one or more processors.

[0108] A medium provided by an embodiment of the present invention stores at least one program code, and when the program code is loaded and executed by a processor.

[0109] The above undisclosed matters can all be implemented by the prior art, so they will not be elaborated here.

[0110] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combinations of these technical features do not conflict, they should all be considered as the scope recorded in this specification.

[0111] The above-described embodiments merely represent several implementation manners of the present invention. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several variations and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the appended claims.

[0112] The foregoing is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A communication traffic anomaly analysis method, characterized in that: The method comprises: S100: Classifying programs into categories, classifying programs in the user terminal into several categories, the categories at least including social, storage and office, and configuring a priority for each category; S200: abnormal program confirmation, constructing a hierarchical monitoring architecture, wherein the hierarchical monitoring architecture includes a basic layer and a monitoring layer, when it is monitored that the communication traffic of the user terminal exceeds the threshold, all the categories are migrated to the basic layer, and traffic is restricted, and the categories are unlocked in order from high to low priority, and the categories of abnormal communication traffic are traversed, and the abnormal category is determined, and the traffic of the programs in the abnormal category is continuously restricted, and they are unlocked in order to find out the abnormal program; S300: abnormal program monitoring, hanging the abnormal program down to the monitoring layer, creating a redundant version, synchronizing the basic data in the abnormal program to the redundant version, and integrating a pre-built complete monitoring mechanism into the hierarchical monitoring architecture; S400: abnormal item confirmation, through the monitoring mechanism, when the communication flow of the abnormal program is monitored to exceed the threshold, the target address of the communication flow is located, the redundant version is triggered to start, the access control list is generated, the target address and the access control list are compared, and the abnormal item is defined; S500: Information integration and transmission, integrating abnormal programs and abnormal items, generating an analysis report, and sending the analysis report to a preset terminal.

2. The communication traffic anomaly analysis method according to claim 1, characterized in that: The S100 includes: The usage frequency of each of the programs is determined, and based on the usage frequency, the priority is dynamically adjusted.

3. The communication traffic anomaly analysis method according to claim 1, characterized in that: The S200 includes: A multi-level restriction mechanism is created and transferred to the hierarchical monitoring architecture, wherein the multi-level restriction mechanism is: when it is monitored that the communication flow of the user terminal exceeds the threshold, it is determined whether the user is using the program, and if so, the program being used is deleted from the category; A root node is marked in the basic layer, the program in use is transferred to the root node, a data transmission channel of the root node is built, and the use authority of the data transmission channel is issued to the program in use.

4. The communication traffic anomaly analysis method according to claim 3, characterized in that: The S200 further includes: Based on the traffic restriction, allocating a traffic quota to each of the categories; The remaining traffic of each category is determined and aggregated to generate a shared traffic pool.

5. The communication traffic anomaly analysis method according to claim 1, characterized in that: The S300 includes: Creating several redundant versions, collecting tasks in the abnormal program, and processing the tasks in parallel using the redundant versions; The abnormal program is split into basic data and configuration data, and the basic data is synchronized into a redundant version.

6. The communication traffic anomaly analysis method according to claim 5, characterized in that: The S400 includes: Record the receiving address of the communication traffic in the abnormal program and define it as the target address; The access control list is drawn using the receiving address of the communication traffic in the redundant version, the difference between the target address and the access control list is compared, and the difference is defined as an abnormal item.

7. A communication traffic anomaly analysis device, characterized in that: The device comprises: A configuration module, used to classify programs in the user terminal into several categories, the categories at least including: social, storage and office, and configure a priority for each of the categories; A search module is used to build a hierarchical monitoring architecture, wherein the hierarchical monitoring architecture includes: a basic layer and a monitoring layer. When it is monitored that the communication flow of the user terminal exceeds the threshold, all the categories are migrated to the basic layer and flow restrictions are performed. The categories are unlocked in order from high to low priority, and the categories with abnormal communication flow are traversed to obtain abnormal categories. The programs in the abnormal categories are continuously restricted in flow, and are unlocked in order to find abnormal programs. An integration module, used to hang the abnormal program down to the monitoring layer, create a redundant version, synchronize the basic data in the abnormal program to the redundant version, and integrate the pre-built monitoring mechanism into the hierarchical monitoring architecture; The sending module is used to locate the target address of the communication traffic through the monitoring mechanism, trigger the start of the redundant version, generate an access control list, compare the target address and the access control list, define the abnormal items, integrate the abnormal program and the abnormal items, generate an analysis report, and send the analysis report to a preset terminal when the communication traffic of the abnormal program exceeds a threshold.

8. The communication traffic anomaly analysis device according to claim 7, wherein the configuration module comprises: The adjustment unit is used to determine the usage frequency of each of the programs and dynamically adjust the priority based on the usage frequency.

9. A terminal, characterized in that: The terminal includes one or more processors and one or more memories, and at least one program code is stored in the one or more memories. When the program code is loaded and executed by the one or more processors, the communication traffic anomaly analysis method according to any one of claims 1 to 6 is implemented.

10. A medium, characterized in that The medium stores at least one program code, and when the program code is loaded and executed by the processor, the communication traffic anomaly analysis method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Illegal external connection monitoring method and device based on data flow analysis and computer equipment

    CN114244571A

  • Network security protection method and system based on flow analysis

    CN116846627A