A network security risk detection method and system based on a Markov chain model
By applying the Markov chain model in network security risk detection, the efficiency and complexity problems of traditional detection technology in the face of complex threats and large data volumes are solved, and more efficient network security risk detection and rapid response are achieved.
Patent Information
- Application Number
- CN202411753278.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-02
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-12-02
AI Technical Summary
Traditional network security risk detection technology is mainly based on signature matching and behavioral analysis, making it difficult to effectively identify zero-day attacks and customize malware. It is highly complex and inefficient when facing large data volumes, and cannot respond quickly to security threats.
The network security risk detection method based on the Markov chain model is adopted, and network security risk detection is carried out by obtaining network traffic data, extracting characteristics and load characteristics, calculating abnormal factors, establishing Markov chain model, calculating state transition probability and support probability, and conducting network security risk detection.
In the face of zero-day attacks and customized malware, the detection effect is significantly improved, and it can quickly process large-scale network traffic data, improving the efficiency and response speed of network security risk detection.
Smart Images

Figure CN119583175B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security detection, and particularly to a network security risk detection method and system based on a Markov chain model. Background Art
[0002] With the rapid development of network technology and the continuous complexity of the network environment, network security issues have become increasingly prominent. Network attack means and strategies continue to evolve, from traditional virus and Trojan attacks to complex forms such as distributed denial of service (DDoS) attacks and advanced persistent threats (APT) today, which pose unprecedented challenges to network security protection. In the face of this situation, modern network security systems not only need to have excellent monitoring capabilities, but also must be able to respond to and adapt to various complex security threats in real time.
[0003] In existing technical solutions, traditional network security risk detection technologies mainly identify threats based on signature matching and behavior analysis. Although these methods are effective in dealing with known threats, their detection effects are poor when facing zero-day attacks and customized malware.
[0004] In addition, with the wide application of big data technology, the amount of network traffic data has increased sharply, resulting in the fact that traditional detection technologies are difficult to quickly process such a large amount of data due to their high complexity and low efficiency, and cannot effectively respond to security threats in the first time. Summary of the Invention
[0005] In order to solve the technical problems that traditional network security risk detection technologies mainly identify threats based on signature matching and behavior analysis, have poor detection effects when facing zero-day attacks and customized malware, and with the wide application of big data technology, the amount of network traffic data has increased sharply, resulting in the fact that traditional detection technologies are difficult to quickly process such a large amount of data due to their high complexity and low efficiency, and cannot effectively respond to security threats in the first time, the present invention provides a network security risk detection method and system based on a Markov chain model.
[0006] The technical solutions provided by the embodiments of the present invention are as follows:
[0007] First aspect:
[0008] A network security risk detection method based on a Markov chain model provided by an embodiment of the present invention includes:
[0009] S1: Obtain network traffic data;
[0010] S2: Extract network traffic characteristics of the network traffic data according to statistical information and metadata of the network traffic data;
[0011] S3: Extract the load characteristics of the network traffic data according to the load of the network traffic data;
[0012] S4: Calculate the anomaly factor of the network traffic data through statistical methods according to the network traffic characteristics and load characteristics of the network traffic data;
[0013] S5: Determine whether there is an anomaly in the network traffic data according to the anomaly factor of the network traffic data; if so, proceed to the next step; otherwise, return to S1 for continuous detection;
[0014] S6: Split the network traffic data into multiple sliding windows;
[0015] S7: Divide the network traffic data in each of the sliding windows into multiple state intervals by the equal-width interval segmentation method;
[0016] S8: Establish a Markov chain model in each of the sliding windows through the Pearson correlation analysis method according to each of the state intervals;
[0017] S9: Calculate the state transition probabilities between each of the state intervals according to the Markov chain model and construct a state transition probability matrix;
[0018] S10: Calculate the support probabilities of the network traffic data in each of the sliding windows under the Markov chain model through the state transition probability matrix;
[0019] S11: Perform network security risk detection according to the support probabilities of each of the network traffic data under the Markov chain model, and determine whether there is an anomaly in the network traffic data; if so, issue an alarm; otherwise, return to S1 for continuous detection.
[0020] Second aspect:
[0021] A network security risk detection system based on a Markov chain model provided by an embodiment of the present invention includes: a memory and one or more processors;
[0022] One or more application programs are stored in the memory, and the one or more application programs are adapted to be executed by the one or more processors to implement the above-mentioned network security risk detection method based on a Markov chain model.
[0023] The beneficial effects brought by the technical solution provided by the embodiment of the present invention at least include:
[0024] In the present invention, by establishing a Markov chain model in each of the sliding windows, threats can be identified without relying on signature matching and behavior analysis, and it has good detection effects against zero-day attacks and customized malware. By calculating the anomaly factor of the network traffic data, based on the anomaly factor of the network traffic data, it is determined whether the network traffic data is abnormal, and based on the support probability of each network traffic data under the Markov chain model, network security risk detection is performed. It has low complexity and high efficiency, can quickly process a large amount of network traffic data, and can effectively respond to security threats in the first time. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention, and for those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0026] Figure 1 FIG. is a schematic flowchart of a network security risk detection method based on a Markov chain model provided by an embodiment of the present invention;
[0027] Figure 2 FIG. is a schematic structural diagram of a network security risk detection system based on a Markov chain model provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] The following will describe the technical solutions in the present invention in conjunction with the drawings.
[0029] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, the use of the word "example" is intended to present concepts in a specific way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two can be selected.
[0030] In order to make the technical problems to be solved, technical solutions and advantages of the present invention clearer, the following will be described in detail in conjunction with the drawings and specific embodiments.
[0031] Refer to the attached description Figure 1 , which shows a schematic flowchart of a network security risk detection method based on a Markov chain model provided by an embodiment of the present invention.
[0032] An embodiment of the present invention provides a network security risk detection method based on a Markov chain model. This method can be implemented by a network security risk detection device based on the Markov chain model, and the network security risk detection device based on the Markov chain model can be a terminal or a server. The processing flow of the network security risk detection method based on the Markov chain model may include the following steps:
[0033] S1: Obtain network traffic data.
[0034] Optionally, by using a network packet capture tool (such as Wireshark or tcpdump), network traffic data transmitted in the network is collected in real time.
[0035] Among them, Wireshark is a network protocol analysis tool, which is usually used to capture and analyze in detail the data packets on a computer network. It provides a graphical interface where users can observe the details of network transmission, including the data of each network layer and the time series of network communication. Wireshark can help network administrators diagnose network problems, analyze the network communication of software applications, learn the specific implementation of network protocols, and check network security issues.
[0036] Among them, tcpdump is a network analysis tool with a command-line interface, which can capture the data packets transmitted in the network. tcpdump is mainly used for UNIX and UNIX-like operating systems and runs through the terminal, allowing users to filter and display data packets according to specified complex criteria (such as port numbers, protocol types, IP addresses, etc.). This tool is an important tool for network administrators or security experts to conduct network monitoring and problem diagnosis, especially useful when quickly and effectively analyzing a large amount of data or performing automated processing.
[0037] In the present invention, by monitoring network traffic in real time, potential anomalies or attack behaviors can be immediately discovered, allowing network administrators to respond quickly to prevent or mitigate the impact of attacks. Real-time data collection ensures the timeliness and effectiveness of the monitoring system.
[0038] S2: Extract the network traffic characteristics of the network traffic data according to the statistical information and metadata of the network traffic data.
[0039] Optionally, the network traffic characteristics include: traffic start time, traffic duration, source byte count, destination byte count, source packet count, and destination packet count.
[0040] Among them, the traffic start time refers to the timestamp when network traffic begins to be transmitted. It usually represents the first time point when a data packet or connection starts to be transmitted. For network security monitoring, the traffic start time can be used to analyze the startup mode of traffic, the time distribution of traffic activities, and potential abnormal behaviors, such as a sudden increase in traffic during abnormal time periods.
[0041] Among them, the traffic duration refers to the time span from the start to the end of network traffic, that is, the active time length of the traffic. It measures the duration of a traffic session or data transmission. A long traffic duration may indicate certain persistent malicious activities, such as DDoS attacks or network scans, etc.
[0042] Among them, the source byte count refers to the total number of bytes of data sent from the source end to the destination end. It reflects the data transmission volume of the source end within a certain period of time and is usually used to evaluate the scale of traffic and whether the traffic is increasing abnormally. For example, an abnormally high source byte count may indicate that the source end is performing large-scale data transmission or an attack.
[0043] Among them, the destination byte count refers to the total number of bytes of data received by the destination end from the source end. It reflects the amount of data received by the destination end and is used to analyze the reverse traffic situation of network communication. An abnormally large destination byte count may indicate that the destination end is receiving a large amount of data, possibly due to service abuse or an attack.
[0044] Among them, the source packet count refers to the number of data packets sent by the source end. It reflects the data transmission frequency of the source end and can help identify the packet sending pattern. An abnormally large source packet count may be related to malicious behaviors, such as brute force cracking attempts, large-scale scans, or intrusion attempts, etc.
[0045] Among them, the destination packet count refers to the number of data packets received by the destination end. It is used to evaluate the frequency and pattern of data received by the destination end. Similar to the source packet count, an abnormally large destination packet count may mean that the destination end is under attack, such as a DDoS attack or a large-scale data theft behavior.
[0046] In the present invention, extracting these specific features can help analyze network behaviors more precisely. For example, through the traffic start time and traffic duration, the patterns and time distributions of network activities can be identified, which is very important for discovering possible abnormal activities (such as high traffic activities at night or during non-working hours). By monitoring the source byte count and destination byte count, the scale and direction of traffic can be evaluated, thereby detecting possible abnormal behaviors, such as data leakage, DDoS attacks, or other forms of network intrusions. The analysis of the source packet count and destination packet count can help identify attack attempts, such as scans, brute force cracking, or other network attack behaviors.
[0047] S3: Extract the load characteristics of the network traffic data based on the load of the network traffic data.
[0048] Among them, the payload refers to the actual data content contained in the data packet, usually the application layer data, such as web page requests, file transfers, email contents, etc. The payload carries the information that the user hopes to transmit, rather than just the control information required by the network protocol (such as the IP header and TCP header).
[0049] Optionally, the load characteristic is specifically: the first 32 bytes of the load content. The first 32 bytes of the load usually contain important information, such as the method, URL, user agent, cookie, etc. in the HTTP request. These information are crucial for identifying user behavior and request types, and help to detect common attack patterns, such as SQL injection, cross-site scripting (XSS), etc.
[0050] It should be noted that directly analyzing the entire load may bring relatively high computing and storage costs, while selecting the first 32 bytes can effectively reduce the complexity of data processing, and still retain sufficient information for feature extraction and analysis.
[0051] In the present invention, directly analyzing the entire load will involve a large amount of data, resulting in a significant increase in computing and storage costs. Selecting to extract the first 32 bytes of the load can significantly reduce the amount of data to be processed, thereby reducing the demand for computing resources and processing time, and improving the overall efficiency of the system. By analyzing the key load content, potential malicious behaviors or abnormal traffic patterns can be monitored and identified more effectively. This is of great significance for timely responding to security threats, preventing data leakage or system intrusion.
[0052] S4: Calculate the anomaly factor of the network traffic data through statistical methods according to the network traffic characteristics and load characteristics of the network traffic data.
[0053] In the present invention, calculating the anomaly factor by combining the network traffic characteristics (such as traffic start and end times, number of data packets, number of bytes, etc.) and load characteristics (such as the specific content of the HTTP request) can more accurately identify abnormal or potential malicious behaviors. This comprehensive analysis can reveal more detailed abnormal patterns and improve the accuracy of anomaly detection. By continuously monitoring the calculated anomaly factor, small changes in network behaviors can be discovered in a timely manner, and these changes may indicate the initial stage of security threats. Early identification and handling of these threats can prevent them from evolving into larger security incidents, thereby protecting network resources from damage.
[0054] In a possible implementation manner, S4 specifically includes sub-steps S401 to S403:
[0055] S401: Concatenate the traffic characteristics and load characteristics of the network traffic data to form a feature vector.
[0056] It should be noted that concatenating the traffic characteristics and load characteristics can effectively integrate information from different sources. Such a comprehensive feature vector can provide a more comprehensive perspective and help better identify complex attack patterns.
[0057] S402: Calculate the standard score of each feature in the feature vector.
[0058] Optionally, calculate the standard score of each feature in the feature vector according to the following formula:
[0059]
[0060] Where, represents the standard score of the k-th feature at time t0, represents the eigenvalue of the k-th feature at time t0, μ k represents the mean of the k-th feature, σ k represents the standard deviation of the k-th feature.
[0061] S403: Calculate the anomaly factor of the network traffic data according to the standard score of each feature.
[0062] Optionally, calculate the anomaly factor of the network traffic data according to the following formula:
[0063]
[0064] Where, represents the anomaly factor of the network traffic data at time t0, β k represents the contribution degree of the k-th feature to network attack detection, and K represents the total number of features.
[0065] It should be noted that the anomaly factor quantifies the deviation degree between each data point and normal behavior, and judges anomalies through a set threshold. This method can effectively identify potential network attacks and abnormal behaviors.
[0066] In the present invention, the network traffic characteristics and load characteristics are concatenated to form a comprehensive feature vector. This method can integrate information from different levels (such as the physical layer, network layer, application layer), providing a more comprehensive view of network behavior. By calculating the standard score of each feature to standardize the eigenvalue, the dimension and scale differences between different features are eliminated. This enables various types of data to be compared and analyzed under the same standard, enhancing the consistency and comparability of data processing. By calculating the anomaly factor to quantify the deviation degree between each data point and normal behavior, anomaly detection becomes more objective and quantifiable.
[0067] S5: Determine whether there is an anomaly in the network traffic data based on the anomaly factor of the network traffic data. If so, proceed to the next step. Otherwise, return to S1 for continued detection.
[0068] In a possible implementation, S5 is specifically as follows:
[0069] Compare the anomaly factor of the network traffic data with the anomaly threshold to determine whether the anomaly factor of the network traffic data is greater than the anomaly threshold. If so, determine that there is an anomaly in the network traffic data and proceed to the next step. Otherwise, determine that there is no anomaly in the network traffic data and return to S1 for continued detection.
[0070] It should be noted that those skilled in the art can set the size of the anomaly threshold according to actual needs, and the present invention does not make any limitations here.
[0071] In the present invention, by comparing the anomaly factor with the threshold in real time, the system can immediately identify abnormal behaviors, reducing the dependence on manual intervention. The automatic judgment process reduces the workload of network administrators and improves the efficiency of network monitoring and management.
[0072] S6: Split the network traffic data into multiple sliding windows.
[0073] It should be noted that the sliding window is a data processing technique that defines a fixed-length window on a data sequence and gradually slides the window position to process the data. Each time it slides, the data range included in the window is updated, enabling continuous analysis of the local characteristics of the data. The sliding window is often used in time series analysis. By moving the window in the data stream, short-term dynamic changes can be captured, thus enabling applications such as real-time monitoring and anomaly detection.
[0074] In the present invention, through the sliding window technique, real-time and continuous monitoring of network traffic can be achieved. This method allows the system to gradually update the data range included in the window in the data stream, thereby promptly capturing any possible anomalies or changes, ensuring the timeliness and continuity of security monitoring. The sliding window can effectively capture the local characteristics of the data and can identify sudden security threats or short-term abnormal behaviors in the field of network security.
[0075] In a possible implementation, S6 is specifically as follows:
[0076] Split the network traffic data into multiple sliding windows according to the following formula:
[0077] W t (l) = {x t-l , x t-l+1 , x t-l+2 , …, x t-1}, where \(t = l + 1, l + 2, \ldots, T\)
[0078] Among them, \(W\) t () represents the sliding window at time \(t\), \(l\) represents the total length of the sliding window, \(x\) represents the network traffic data, \(t\) represents the time, and \(T\) represents the total duration.
[0079] In the present invention, by dividing into multiple sliding windows, fine-grained analysis of network traffic can be performed. This method allows independent evaluation of the data within each window, thereby more accurately capturing network behavior and potential abnormal patterns within a specific time period. Dividing the traffic data into multiple time windows enables the system to detect and analyze the data within each window in real time, quickly identify and respond to sudden network security events.
[0080] S7: By the equal-width interval segmentation method, the network traffic data in each sliding window is divided into multiple state intervals.
[0081] It should be noted that the equal-width interval segmentation method is a technique for dividing continuous data into multiple fixed-width intervals. Specifically, it evenly divides the entire data range into several equal-width intervals according to the minimum and maximum values of the data, and each interval represents a state or category. Such a method is commonly used in data processing and discretization, especially suitable for converting continuous variables into discrete states in the case of relatively uniform data distribution, facilitating subsequent analysis and modeling, such as for state definition in Markov chain models.
[0082] It should be noted that a state interval refers to dividing a continuous data or numerical range into multiple discrete intervals, and each interval represents a specific state. By mapping the data to these predefined intervals, complex continuous data can be transformed into a finite number of discrete states for modeling and analysis. For example, in network traffic analysis, the traffic data is divided into "low", "medium", and "high" state intervals according to the magnitude of the data values, which can simplify data processing and facilitate state transition analysis and anomaly detection using models such as Markov chains.
[0083] Among them, the width of each state interval is specifically:
[0084]
[0085] Among them, \(\omega\) represents, \(\max()\) represents taking the maximum value, \(W\) t () represents the sliding window at time \(t\), \(l\) represents the length of the sliding window, \(\min()\) represents taking the minimum value, and \(N\) represents the total number of state intervals.
[0086] In the present invention, continuous network traffic data is discretized into multiple state intervals with a fixed width, which simplifies the complexity of data processing. Equal-width interval division provides a unified format for the data, enabling different data points to be processed and compared in the same way. Dividing network traffic into different state intervals such as "low", "medium", and "high" makes monitoring and reporting more intuitive. Network administrators can quickly identify which intervals have abnormal traffic and thus take corresponding security measures.
[0087] S8: According to each state interval, establish a Markov chain model in each sliding window through the Pearson correlation analysis method.
[0088] It should be noted that the Pearson correlation analysis method is a statistical method used to measure the degree of linear correlation between two variables. It represents the relationship between variables by calculating the Pearson correlation coefficient (the value range is from -1 to 1): when the coefficient is close to 1, it indicates a strong positive correlation between the two variables. Close to -1 indicates a strong negative correlation. Close to 0 indicates almost no correlation. The Pearson correlation analysis is widely used in data analysis to determine whether there is a significant linear relationship between variables, thus helping to understand the internal connections and patterns of the data.
[0089] It should be noted that the Markov chain model is a mathematical model used to describe the state changes of a system, where the next state of the system depends only on the current state and is independent of the previous states, which is called "Markov property" or "memorylessness". In a Markov chain, the transitions between states are based on certain probabilities, and these probabilities form the state transition probability matrix. The Markov chain model is widely applied in time series analysis and prediction. For example, in network security, it can be used to simulate normal state transition patterns to identify abnormal behaviors.
[0090] In the present invention, by calculating the Pearson correlation coefficient to evaluate the correlation between different state intervals, it is possible to accurately determine which states have a significant linear relationship. This helps to establish a more accurate Markov chain model, where the state transition probabilities are obtained based on the actual data relationships, improving the accuracy and reliability of the model prediction. The memoryless feature of the Markov chain means that the prediction of the next state depends only on the current state. By applying the Pearson correlation analysis and establishing a Markov model within each sliding window, it is possible to effectively capture the state dependencies and change patterns in the short term.
[0091] In a possible implementation manner, S8 specifically includes sub-steps S801 and S802:
[0092] S801: Through the Pearson correlation analysis method, calculate the Pearson correlation coefficients between each sliding window:
[0093]
[0094] Among them, r() represents the Pearson correlation coefficient, n represents the order of the Markov chain model, l represents the total length of the sliding window, x represents the network traffic data, and t represents the time.
[0095] S802: According to each state interval, when the Pearson correlation coefficient is greater than or equal to the preset value, establish a Markov chain model in each sliding window:
[0096] λ(n) = {S, Q, P n}
[0097] Among them, λ(n) represents the nth-order Markov chain model, S represents the total number of state spaces, Q represents the set of initial state transition probabilities of the state space, and P n represents the nth-order state transition probability matrix.
[0098] It should be noted that those skilled in the art can set the size of the preset value according to actual needs, and the present invention does not limit this here.
[0099] In the present invention, by calculating the Pearson correlation coefficient between sliding windows, the linear correlation between data can be accurately identified. This correlation indicates that the data is similar or related to a certain extent, which helps to select a suitable window as the basis for the Markov chain model, thereby constructing a more accurate and representative state model. Based on the accurately constructed Markov chain model, the change of the network state can be monitored more effectively, and potential security threats can be predicted. When an abnormal state transition probability is detected, the system can issue a warning in time and take corresponding security measures.
[0100] S9: According to the Markov chain model, calculate the state transition probabilities between each state interval and construct a state transition probability matrix.
[0101] In the present invention, the state transition probability matrix provides the system with the transition probability from each state to other states, which enables the model to accurately predict future state changes. By updating the state transition probability matrix in real time, the system can quickly respond to the change of the network state and provide instant security decision support. The state transition probability matrix not only provides the prediction result of the model, but also clarifies the conversion relationship between different states, which enhances the transparency and interpretability of the model.
[0102] In a possible implementation manner, S9 specifically includes sub-steps S9010 and S902:
[0103] S901: According to the order of the Markov chain model, calculate the state transition probabilities between each state interval:
[0104]
[0105] Among them, represents the n-step state transition probability of transitioning from the state interval at time t-1 to the state interval at time t, represents the number of n-step state transitions from the state interval at time t-1 to the state interval at time t, where n represents the order of the Markov chain model, and s t-1 represents the state interval at time t-1, and s t represents the state interval at time t, and N represents the total number of state intervals.
[0106] S902: Construct a state transition probability matrix based on the state transition probabilities between each state interval:
[0107]
[0108] Among them, P n represents the nth-order state transition probability matrix.
[0109] In the present invention, by calculating the state transition probabilities of different orders (n), deep patterns of state changes can be captured. In a high-order Markov chain, the determination of the current state depends not only on the previous state but on multiple previous states, which can more comprehensively reflect the historical dependence of the state and improve the prediction accuracy of the model. Constructing state transition probability matrices of different orders enables the model to flexibly adapt to various complex situations. Such a multi-order model can better adapt to the actual dynamics of network behavior, especially in scenarios where network traffic is complex or has long-term dependencies.
[0110] S10: Calculate the support probabilities of the network traffic data in each sliding window under the Markov chain model through the state transition probability matrix.
[0111] It should be noted that the support probability is, in a probability model, the conditional probability of a given output or result occurring, usually based on the information of the current state or input of the model. In a Markov chain or other state-based models, the support probability specifically refers to the probability that a specific state or event sequence is considered to be true or valid in the model. This probability helps to judge the "support degree" of the model for a certain state or event chain and is used for decision-making, predicting future states, or evaluating the possibility of a certain situation. For example, in network security monitoring, the support probability can be used to evaluate the possibility that a certain network behavior sequence belongs to normal or abnormal.
[0112] In the present invention, by using the support probability calculated in real time, the system can quickly identify and respond to potential security threats. The calculation of the support probability enables the model to adapt to the changing network environment and behavior patterns. By learning from historical data and analyzing real-time data, the model can continuously adjust its state transition probability to reflect the latest network behaviors and threat trends.
[0113] In a possible implementation manner, S10 is specifically as follows:
[0114] According to the following formula, calculate the support probability of the network traffic data in the sliding window under the Markov chain model:
[0115]
[0116] where P(x t |λ(n)) represents the support probability of the network traffic data at time t under the n - order Markov chain model, represents the initial state transition probability of the state interval at time t - n, represents the i - step state transition probability from the state interval at time t - i to the state interval at time t, and ∏ represents the product operation.
[0117] In the present invention, by calculating the support probability of the network traffic data at each time t under the n - order Markov chain model, the probability of the current network state can be judged more accurately. This method provides a reliable prediction of future states based on the actually observed past n states, thus greatly improving the accuracy of network behavior analysis. By using the method of combining a sliding window and an n - order Markov chain model, the change of the network state can be dynamically tracked, and the short - term behavior dynamics can be captured.
[0118] S11: According to the support probability of each network traffic data under the Markov chain model, perform network security risk detection to determine whether there is an abnormality in the network traffic data. If so, issue an alarm. Otherwise, return to S1 to continue the detection.
[0119] Specifically, S11 specifically includes:
[0120] When the support probability of the network traffic data under the Markov chain model is equal to 0, it is determined that there is an abnormality in the network traffic data, and an alarm is issued.
[0121] When the support probability of the network traffic data under the Markov chain model is not equal to 0, it is determined that there is no abnormality in the network traffic data.
[0122] In the present invention, the decision - making based on the support probability makes the response measures more data - driven, reducing the false alarm rate and the missed alarm rate. The analysis of the support probability is not only used to detect current abnormalities, but also can be used to predict future possible security events.
[0123] In a possible implementation, after S11, it further includes:
[0124] S12: Through an anomaly replacement strategy, select the network traffic data with the maximum support probability in each sliding window to replace the attack network traffic:
[0125]
[0126] where x t ′ represents the network traffic data with the maximum support probability at time t, arg max represents taking the maximum value, and x t represents the network traffic data at time t, W t () represents the sliding window at time t, l represents the length of the sliding window, and P(x t |λ(n)) represents the support probability of the network traffic data at time t under the nth-order Markov chain model.
[0127] In the present invention, replacing the traffic data identified as an attack can mitigate or block the impact of malicious activities in real time. By using the data with the maximum support probability to replace the abnormal data, the system can maintain the normal operation of the network, while isolating or reducing the damage caused by the attack. Selecting the data with the maximum support probability as the replacement helps to quickly restore to the normal network state, ensuring the continuity and stability of network services. After replacing the attack traffic, subsequent data processing and analysis can be carried out in a cleaner data environment closer to the normal state. This helps to improve the accuracy and efficiency of data analysis and avoid misjudgments caused by the influence of attacked data.
[0128] The beneficial effects brought by the technical solution provided by the embodiments of the present invention at least include:
[0129] In the present invention, by establishing a Markov chain model in each of the sliding windows, threats can be identified without relying on signature matching and behavior analysis, and it has good detection effects against zero-day attacks and customized malware. By calculating the anomaly factor of the network traffic data, judging whether the network traffic data is abnormal according to the anomaly factor of the network traffic data, and performing network security risk detection according to the support probability of each network traffic data under the Markov chain model, it has low complexity and high efficiency, can quickly process a large amount of network traffic data, and can effectively respond to security threats in the first time.
[0130] Referring to the attached drawings of the specification Figure 2 , a schematic structural diagram of a network security risk detection system provided by the present invention is shown.
[0131] The present invention also provides a network security risk detection system 30 based on a Markov chain model, including: a memory 303 and one or more processors 301.
[0132] One or more applications are stored in the memory 303, and the one or more applications are adapted to be executed by the one or more processors 301 to implement the network security risk detection method based on the Markov chain model described in the method embodiments.
[0133] The network security risk detection system 30 based on the Markov chain model includes: a processor 301 and a memory 303. Among them, the processor 301 and the memory 303 are connected, such as connected through a bus 302.
[0134] The structure of the network security risk detection system 30 based on the Markov chain model does not constitute a limitation to the embodiments of the present invention.
[0135] The processor 301 can be a CPU, a general-purpose processor, a DSP, an ASIC, an FPGA or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in combination with the disclosure of the present invention. The processor 301 can also be a combination that realizes computing functions, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0136] The bus 302 may include a path for transmitting information between the above components. The bus 302 can be a PCI bus or an EISA bus, etc. The bus 302 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus.
[0137] The memory 303 can be a ROM or other types of static storage devices that can store static information and instructions, a RAM or other types of dynamic storage devices that can store information and instructions, or an EEPROM, a CD-ROM or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but not limited thereto.
[0138] It should be noted that the network security risk detection system 30 based on the Markov chain model can implement the above-mentioned network security risk detection method based on the Markov chain model and can achieve the same or similar technical effects. To avoid repetition, the present invention will not be described in detail herein.
[0139] The beneficial effects brought by the technical solution provided by the embodiment of the present invention at least include:
[0140] In the present invention, by establishing a Markov chain model in each of the sliding windows, threats can be identified without relying on signature matching and behavior analysis, and it has good detection effects against zero-day attacks and customized malware. By calculating the anomaly factor of the network traffic data, based on the anomaly factor of the network traffic data, it is determined whether the network traffic data is abnormal, and based on the support probability of each network traffic data under the Markov chain model, network security risk detection is performed. It has low complexity and high efficiency, can quickly process a large amount of network traffic data, and can effectively respond to security threats in the first time.
[0141] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
[0142] The following points need to be explained:
[0143] (1) The attached drawings of the embodiment of the present invention only relate to the structure involved in the embodiment of the present invention, and other structures can refer to the general design.
[0144] (2) For clarity, in the attached drawings used to describe the embodiments of the present invention, the thickness of layers or regions is enlarged or reduced, that is, these drawings are not drawn according to the actual scale. It can be understood that when an element such as a layer, film, region, or substrate is referred to as being "on" or "under" another element, the element can be "directly" on or under the other element or there can be intermediate elements.
[0145] (3) Without conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other to obtain new embodiments.
[0146] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. The protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A network security risk detection method based on a Markov chain model, characterized in that: include: S1: Obtain network traffic data; S2: extracting network traffic features of the network traffic data according to the statistical information and metadata of the network traffic data; S3: extracting load characteristics of the network traffic data according to the load of the network traffic data; S4: Calculating the abnormal factors of the network traffic data by statistical methods according to the network traffic characteristics and load characteristics of the network traffic data; S5: judging whether the network traffic data is abnormal according to the abnormal factor of the network traffic data; If yes, go to the next step; otherwise, return to S1 to continue testing; S6: dividing the network traffic data into a plurality of sliding windows; S7: dividing the network traffic data in each sliding window into a plurality of state intervals by an equal-width interval segmentation method; S8: According to each of the state intervals, a Markov chain model is established in each of the sliding windows by using a Pearson correlation analysis method; S9: According to the Markov chain model, the state transition probability between each state interval is calculated and a state transition probability matrix is constructed; S10: calculating the support probability of the network traffic data in each of the sliding windows under the Markov chain model through the state transition probability matrix; S11: Performing network security risk detection according to the support probability of each network traffic data under the Markov chain model to determine whether the network traffic data is abnormal; If so, sound the alarm; Otherwise, return to S1 to continue testing.
2. The network security risk detection method based on the Markov chain model according to claim 1 is characterized in that: The network traffic characteristics include: traffic start time, traffic duration, source byte number, target byte number, source data packet number and target data packet number.
3. The network security risk detection method based on the Markov chain model according to claim 1 is characterized in that: The S4 specifically includes: S401: concatenating the flow characteristics and load characteristics of the network flow data to form a feature vector; S402: Calculate the standard score of each feature in the feature vector; S403: Calculate the abnormal factor of the network traffic data according to the standard score of each feature.
4. The network security risk detection method based on the Markov chain model according to claim 1 is characterized in that: The S5 is specifically: Compare the abnormal factor of the network traffic data with the abnormal threshold to determine whether the abnormal factor of the network traffic data is greater than the abnormal threshold; if so, determine that the network traffic data is abnormal, and proceed to the next step; Otherwise, it is determined that there is no abnormality in the network traffic data, and the process returns to S1 to continue detection.
5. The network security risk detection method based on the Markov chain model according to claim 1 is characterized in that: The S8 specifically includes: S801: Calculate the Pearson correlation coefficient between each sliding window by using the Pearson correlation analysis method: Among them, r() represents the Pearson correlation coefficient, n represents the order of the Markov chain model, l represents the total length of the sliding window, x represents the network traffic data, and t represents the time; S802: According to each of the state intervals, when the Pearson correlation coefficient is greater than or equal to a preset value, a Markov chain model is established in each of the sliding windows: λ(n)={S,Q,P n } Among them, λ(n) represents the n-order Markov chain model, S represents the total number of state spaces, Q represents the initial state transition probability set of the state space, P n Represents the n-order state transition probability matrix.
6. The network security risk detection method based on the Markov chain model according to claim 1 is characterized in that: The S9 specifically includes: S901: Calculate the state transition probability between each state interval according to the order of the Markov chain model: in, represents the n-step state transition probability from the state interval at time t-1 to the state interval at time t, represents the number of n-step state transitions from the state interval at time t-1 to the state interval at time t, n represents the order of the Markov chain model, s t-1 represents the state interval at time t-1, s t represents the state interval at time t, and N represents the total number of state intervals; S902: Construct a state transition probability matrix according to the state transition probabilities between the state intervals: Among them, P n Represents the n-order state transition probability matrix.
7. The network security risk detection method based on the Markov chain model according to claim 1 is characterized in that: The S10 is specifically: The support probability of the network traffic data in the sliding window under the Markov chain model is calculated according to the following formula: Among them, P(x t |λ(n)) represents the support probability of the network traffic data at time t under the n-order Markov chain model, represents the initial state transition probability of the state interval at time tn, It represents the i-step state transition probability from the state interval at time ti to the state interval at time t, and ∏ represents the continuous multiplication operation.
8. The network security risk detection method based on the Markov chain model according to claim 1 is characterized in that: The S11 specifically includes: When the support probability of the network traffic data under the Markov chain model is equal to 0, it is determined that the network traffic data is abnormal and an alarm is issued; When the support probability of the network traffic data under the Markov chain model is not equal to 0, it is determined that there is no abnormality in the network traffic data.
9. The network security risk detection method based on the Markov chain model according to claim 1 is characterized in that: After S11, the method further includes: S12: Using an abnormal replacement strategy, select the network traffic data with the maximum support probability in each sliding window to replace the attack network traffic: Among them, x t ′ represents the network traffic data with the maximum support probability at time t, arg max represents the maximum value, x t represents the network traffic data at time t, W t () represents the sliding window at time t, l represents the length of the sliding window, P(x t |λ(n)) represents the support probability of the network traffic data at time t under the n-order Markov chain model.
10. A network security risk detection system based on a Markov chain model, characterized in that: include: memory and one or more processors; One or more applications are stored in the memory, and the one or more applications are suitable for being executed by the one or more processors to implement the network security risk detection method based on the Markov chain model as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Traffic behavior analysis method oriented to distributed network
CN108923975A
Flow anomaly detection method based on multi-order Markov chain
CN110460458A