Virus monitoring and early warning method based on deep analysis of network traffic

Through the method based on in-depth analysis of network traffic, abnormal behaviors in network traffic are detected in real time, equipment infection status is dynamically modeled, and virus transmission trends are simulated using the propagation graph model, the problem of dependence on virus signature in the existing technology is solved, accurate monitoring and transmission trend prediction of unknown viruses and mutant viruses is achieved, and defense strategies are optimized.

CN119583215BActive Publication Date: 2025-05-13BEIJING EASYNETWORKS TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510112637.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-13
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

The existing virus surveillance methods are highly dependent on virus signatures, making it difficult to effectively deal with unknown viruses and mutant viruses. At the same time, it lacks in-depth monitoring of potential threats from internal networks, making it difficult to accurately predict the spread path and infection range of viruses.

Method used

Using a method based on deep analysis of network traffic, the traffic data is collected in real time through deep packet detection technology, the traffic characteristics are extracted and an abnormal behavior detection model is established to detect abnormal patterns that deviate from normal behavior. Combined with dynamic modeling of device infection status, infection risk is quantified, and virus transmission trends are simulated by building device interactive propagation graph models and transmission dynamic equations, early warning information is generated and defense strategies are optimized.

Benefits of technology

It realizes accurate monitoring of unknown viruses and mutant viruses, improves detection accuracy of potential virus threats, accurately simulates virus transmission trends, optimizes defense resource allocation, and significantly enhances the defense effect of the virus monitoring system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583215B_ABST
    Figure CN119583215B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology, and discloses a virus monitoring and early warning method based on deep analysis of network traffic, including the following steps: collecting network traffic data in real time through deep packet detection technology, extracting traffic features, and constructing a traffic feature sequence based on a time window; establishing an anomaly detection model based on the traffic feature sequence to identify abnormal patterns that deviate from normal behavior distribution; constructing a dynamic model of the device infection state based on the abnormal behavior detection results to quantify the risk of device infection; constructing a propagation graph model in combination with the device interaction relationship, and simulating the virus diffusion path and propagation trend in the network based on propagation dynamics. The present invention can accurately monitor the hidden behaviors of unknown viruses and mutant viruses, dynamically predict the virus propagation path and impact range, and at the same time combine game theory and linear programming to achieve the optimal allocation of defense resources, thereby improving the real-time nature of virus monitoring and defense.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a virus monitoring and early warning method based on in-depth analysis of network traffic. Background Art

[0002] With the rapid development of information technology, the network has become an important infrastructure in modern society. However, network security threats are becoming increasingly serious. Virus attacks, as a typical network threat, can not only damage a single device, but also spread through the network to cause large-scale system paralysis. In order to cope with virus threats, various virus monitoring and early warning technologies are constantly developing. However, current monitoring methods still have significant deficiencies in practical applications.

[0003] Traditional virus monitoring technology usually relies on feature matching or signature recognition, that is, detecting malicious traffic by matching the signature code of known viruses. This method has high accuracy in detecting known viruses, but faces the following key problems: First, the reliance on virus features makes these methods difficult to deal with unknown viruses and mutant viruses. With the continuous evolution of virus technology, new viruses often evade feature matching through encryption, disguise or mutation, which significantly reduces the detection efficiency of traditional methods. Secondly, these methods lag in the timeliness of feature library updates. The improvement of feature libraries often requires a lot of time for analysis and extraction after the virus outbreak, resulting in the defense system lacking effective response capabilities when actual attacks occur. In addition, existing virus monitoring systems usually perform preliminary screening of network edge traffic and lack in-depth monitoring of potential threats in the internal network, so the risk of virus transmission within the network cannot be effectively controlled.

[0004] In terms of virus propagation prediction and early warning, existing methods are mainly based on static network topology or simple propagation models, which cannot dynamically reflect the complex behavioral characteristics of virus propagation. Especially when facing large and complex networks, it is difficult to accurately predict the virus spread path and infection range. For the optimal allocation of defense resources, traditional methods lack systematic strategies and often cannot achieve priority protection of key nodes and paths under limited resource conditions, resulting in poor defense effects. Summary of the invention

[0005] In view of the shortcomings of the prior art, the present invention provides a virus monitoring and early warning method based on in-depth analysis of network traffic.

[0006] This solves the problem that existing virus monitoring methods are highly dependent on virus feature signatures and are difficult to effectively deal with unknown viruses and mutant viruses.

[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: A virus monitoring and early warning method based on deep analysis of network traffic, comprising the following steps:

[0008] Use deep packet inspection technology to collect traffic data in real time, extract traffic features, and divide them into traffic feature sequences based on time windows;

[0009] An abnormal behavior detection model is established based on the traffic feature sequence to detect abnormal patterns in traffic that deviate from the normal behavior distribution;

[0010] Based on the abnormal behavior detection results, a dynamic model of the device infection status is established to conduct infection risk assessment;

[0011] Build a propagation graph model of device interaction based on propagation dynamics to simulate the prediction of virus propagation trends in the network;

[0012] Generate early warning and defense optimization information based on the propagation trend prediction results.

[0013] Preferably, the flow data collection comprises the following steps:

[0014] Extract the traffic characteristics of data packets in the network through deep packet inspection technology:

[0015] The traffic data is divided using the time window mechanism, the features within the time window are extracted as feature vectors, and the traffic feature matrix is ​​generated.

[0016] Preferably, the abnormal behavior detection comprises the following steps:

[0017] Based on the Gaussian process model, the normal behavior of traffic characteristics is modeled and a traffic prediction model is established;

[0018] By calculating the deviation of traffic characteristics, anomaly scores are generated and abnormal behavior is detected.

[0019] Preferably, in the infection risk assessment step, the device infection status S i (t) is described by the following differential equation: dS i =βS i (1-S i )dt+σS i dW t Where β is the propagation rate, σ is the noise intensity, dW t For Brownian motion;

[0020] By numerically solving the stochastic differential equation, the infection probability S of the device at a future time point is predicted. i (t+Δt).

[0021] Preferably, the propagation trend prediction comprises the following steps:

[0022] Construct a propagation graph model and assign weights to represent communication strength;

[0023] Based on the infection status and propagation path of the device, the propagation dynamics model is used to predict the spread and trend of the virus in the network.

[0024] Preferably, the early warning and defense optimization comprises the following steps:

[0025] Calculate the infection risk index based on the device infection probability and the device importance weight;

[0026] Generate early warning information based on infection risk indicators, including identification of high-risk devices and prediction of virus transmission paths;

[0027] Optimize defense strategies based on game theory, dynamically adjust defense resource allocation, prioritize protection of key equipment, and prevent virus spread.

[0028] Preferably, the defense optimization constructs an adversarial game model, in which the attacker spreads the virus by selecting key device nodes, and the defender suppresses the virus propagation by selecting and protecting key device nodes, thereby solving the optimal defense strategy to reduce network propagation.

[0029] Preferably, in the defense optimization step, the defense strategy protects devices with high propagation criticality by dynamically adjusting the defense priority according to the propagation criticality of the devices.

[0030] Preferably, the construction of the propagation graph model is represented by the following formula: in, is the equipment set, E t is the set of communication edges at time t.

[0031] A virus monitoring and early warning system based on deep analysis of network traffic, the system comprising:

[0032] Traffic collection module, used to collect traffic data and extract traffic features through deep packets;

[0033] Anomaly detection module, used to detect abnormal behavior in traffic based on Gaussian process model;

[0034] The infection risk assessment module is used to describe the dynamic evolution of the device infection state using stochastic differential equations;

[0035] The transmission trend prediction module is used to construct a transmission map and simulate the virus's transmission path;

[0036] The early warning and defense module is used to generate early warning information and optimize defense strategies based on game theory.

[0037] The present invention provides a virus monitoring and early warning method based on in-depth analysis of network traffic. It has the following beneficial effects:

[0038] 1. The present invention effectively gets rid of the reliance of traditional virus monitoring technology on feature signature libraries by deeply analyzing traffic characteristics and building an anomaly detection model based on Gaussian processes, and can accurately identify the hidden behaviors of unknown viruses and mutant viruses. By modeling the distribution characteristics of normal traffic and capturing deviation behaviors, the present invention significantly improves the detection accuracy of potential virus threats, especially showing strong adaptability when facing complex and diverse traffic environments.

[0039] 2. Based on the propagation graph model and propagation dynamics equation, the present invention constructs a mathematical description framework for virus propagation, which can accurately simulate the virus spreading process between devices. By combining the device infection status, propagation path and node interaction relationship, the virus propagation trend and infection range are dynamically predicted, providing a scientific basis for the generation of early warning information, and significantly enhancing the virus monitoring system's ability to assess the risk of virus spread.

[0040] 3. The key node priority model and resource optimization allocation strategy proposed in the present invention can comprehensively consider the equipment risk indicators and propagation trends, and achieve the optimal allocation of defense resources through game theory and linear programming methods. By giving priority to protecting highly critical nodes, the present invention effectively inhibits the spread of viruses, reduces the scope of infection and the speed of propagation, and ensures the maximization of defense effectiveness under the constraints of limited resources.

[0041] 4. The present invention can adapt to the changes in traffic and device interaction characteristics in the network environment by dynamically adjusting the propagation graph weights and updating the propagation dynamics parameters in real time, and maintain the real-time and accuracy of virus monitoring and defense. At the same time, the modular design and flexible parameter adjustment mechanism of the present invention give it strong adaptability and scalability, and can be widely used in a variety of complex network scenarios, including enterprise networks, Internet of Things environments, and cloud computing platforms. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 It is a schematic diagram of the method flow of the present invention;

[0043] Figure 2 It is a schematic diagram of the system structure of the present invention. DETAILED DESCRIPTION

[0044] The following will be combined with the drawings in the specification of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0045] Please see attached Figure 1 The embodiment of the present invention provides a virus monitoring and early warning method based on deep analysis of network traffic, comprising the following steps:

[0046] S1. Use deep packet inspection technology to collect traffic data in real time, extract traffic features, and divide them into traffic feature sequences based on time windows;

[0047] S2. Establish an abnormal behavior detection model based on the traffic feature sequence to detect abnormal patterns in the traffic that deviate from the normal behavior distribution;

[0048] S3. Based on the abnormal behavior detection results, a dynamic model of the device infection status is established to conduct infection risk assessment;

[0049] S4. Construct a propagation graph model of device interaction based on propagation dynamics to simulate the prediction of virus propagation trends in the network;

[0050] S5. Generate early warning and defense optimization information based on the propagation trend prediction results.

[0051] In this embodiment, with respect to step S1, a data packet transmitted in the network is acquired through deep packet inspection technology, specific fields in the data packet are parsed, and dynamic features of the traffic are extracted in combination with a time window mechanism.

[0052] It should be noted that the time window-based partitioning mechanism can effectively process traffic behavior in a time series manner, providing technical support for capturing dynamic anomalies and traffic regularity. At the same time, when extracting features, it is necessary to comprehensively consider the characteristics of encrypted and non-encrypted traffic, and generate high-dimensional, multi-level feature sequences as much as possible to meet the needs of subsequent modeling.

[0053] In this embodiment, real-time collection and analysis of network traffic is achieved through DPI technology. Specifically:

[0054] Traffic data collection During the network data collection process, deep packet inspection technology is used to analyze the main fields of network traffic packet by packet, including:

[0055] Packet size: records the actual number of bytes in the data packet;

[0056] Communication protocol: identifies the protocol type to which the data packet belongs;

[0057] IP address: includes the source IP address and destination IP address of the data packet, used to distinguish the communication peers;

[0058] Timestamp: records the time when the data packet is captured, which is used for time dimension analysis of traffic.

[0059] As an option, DPI technology can be implemented through high-performance traffic capture tools. These tools can support real-time capture and field analysis of data packets in a multi-protocol environment and are suitable for large-scale and complex networks.

[0060] It should be noted that, in order to avoid redundancy in data collection, the present invention adopts a metadata-based collection strategy. For example, for HTTPS traffic, only the information in the TLS handshake phase is extracted without attempting to decrypt the traffic content.

[0061] In this embodiment, in order to extract the core dynamic features of network traffic, traffic data is divided and counted based on a time window mechanism. Specifically, each time window is set to Δt seconds, and traffic data is counted within the window.

[0062] The extracted traffic features include but are not limited to the following:

[0063] Packet size distribution: Statistics of the average packet size of all data packets within the time window and standard deviation σ p The calculation formula is as follows: Where N is the number of packets in the time window, p i is the size of the ith data packet.

[0064] Communication frequency: The number of session connections (including connection establishment and disconnection times) within the statistical time window is used to describe the interaction intensity between devices.

[0065] Protocol distribution: records the traffic proportion of various protocols within the time window, such as the proportion of DNS, HTTP, HTTPS and other protocol traffic.

[0066] As an implementation method, the above statistical features can be represented by feature vectors: X t =[f1, f2, ..., f n ] Where fi is the statistical value of a certain type of traffic characteristics.

[0067] In some embodiments, in order to capture the dynamic change trend of traffic characteristics, a sliding window mechanism can be used to expand the time range of the feature sequence. Specifically:

[0068] The extended feature matrix is ​​constructed using the feature vectors of continuous time windows. For example, for the time window, t-2, t-1, t, the extended feature matrix is ​​expressed as: Among them, f i t-k Represents the feature fi in the kth time window. This method retains the time series characteristics of traffic characteristics and provides richer input for subsequent modeling.

[0069] It should be noted that the step size of the sliding window can be dynamically adjusted according to the specific application scenario. For example, the step size can be smaller than the time window length to enhance time correlation, or it can be equal to the time window length to reduce computational complexity.

[0070] In a possible implementation, in order to further improve the expressiveness of features, the present invention may also introduce the following advanced features:

[0071] Inter-packet time interval: Calculate the difference in the sending time of adjacent data packets within the time window, expressed as: Δt i =t i+1 -t i Among them, t i is the capture time of the i-th data packet.

[0072] Directional traffic characteristics: The forward traffic from the source IP to the target IP and the reverse traffic from the target IP to the source IP are counted separately to describe the directional characteristics of the communication.

[0073] TLS handshake characteristics (applicable to encrypted traffic): Extract information from the TLS handshake phase, such as certificate type, negotiated cipher suite, etc.

[0074] The above features can be combined with basic statistical features to construct high-dimensional feature vectors and improve the ability of subsequent models to identify complex network traffic.

[0075] When processing large-scale traffic, in order to reduce the computational overhead of feature extraction, some embodiments may use feature compression technology. For example, for IP pairs that communicate frequently, their traffic statistics may be merged;

[0076] For the statistical results of protocol traffic proportion, the protocol types with extremely low proportion can be ignored.

[0077] Through the above optimization, the processing efficiency can be improved while ensuring the feature expression capability.

[0078] It should be understood that through the processing of this step, the network traffic characteristics are finally represented as a time series matrix The flow data is formulated as: Among them, X T is the traffic feature vector within the time window T, and the feature dimension n is selected according to the specific features.

[0079] Through the above method, the present invention can accurately extract traffic patterns in high-dimensional dynamic features, laying a foundation for subsequent anomaly detection and infection risk assessment.

[0080] In this embodiment, for step S2, in order to accurately identify virus behavior, the present invention constructs an abnormal behavior detection model based on traffic feature sequences to effectively detect abnormal patterns in network traffic that deviate from normal behavior distribution. The role of this step in this method is to provide accurate input data for subsequent infection risk assessment and propagation trend prediction. By analyzing traffic features in real time and combining anomaly detection models, the present invention can quickly discover potential virus activities and lay the foundation for early warning.

[0081] It should be noted that the construction of the traffic feature sequence is based on the dynamic division of the time window, and is combined with the anomaly detection model to accurately capture abnormal behaviors. This step is described in detail below in conjunction with a specific implementation method.

[0082] The construction of traffic feature sequences first analyzes network traffic through deep packet inspection technology, extracts key features, and divides traffic into feature sequences based on time windows. It should be noted that the division of time windows is the key basis for building a traffic dynamic model.

[0083] Specifically, the extracted traffic features include:

[0084] Packet size distribution: Within the time window Δt, the distribution of statistical packet sizes is collected and its mean, variance and other statistical indicators are calculated: Where N is the number of packets in the window, p i is the size of the ith data packet.

[0085] Traffic rate: Calculates the transmission rate per unit time and is defined as: Protocol usage distribution: Statistics on the usage frequency of common protocols within the window and records them as feature vectors.

[0086] Time series features: Record session duration and connection frequency to characterize the dynamic behavior of traffic.

[0087] Alternatively, these features can be represented as a feature matrix X t

[0088] : Among them, f i t is the value of the i-th feature in the t-th time window, and T is the total number of windows.

[0089] It should be noted that the size of the time window Δt is dynamically adjusted according to the real-time requirements of the specific network environment. For example, a smaller time window (such as 1 second) can be selected in a high-traffic environment to improve real-time performance.

[0090] In this embodiment, the distribution of traffic features is modeled by Gaussian process to capture abnormal behaviors that deviate from normal distribution. Gaussian process is a non-parametric Bayesian method that can describe the correlation of data through covariance function.

[0091] The Gaussian process is defined as: f(x)~GP(μ(x), K(x, x′)), where μ(x) is the mean function, which is used to describe the expected value of the traffic characteristics, and K(x, x′) is the covariance function, which describes the correlation between the characteristic values.

[0092] Exemplarily, the covariance function may select a radial basis kernel, which is defined as follows: is the signal amplitude, indicating the fluctuation range of the eigenvalue, and l is the scale parameter, which controls the decay speed of the eigenvalue correlation.

[0093] It should be noted that the mean function μ(x) can take a constant zero mean or be fitted according to historical data to more accurately reflect the normal traffic distribution.

[0094] In one possible implementation, the training and prediction process of the Gaussian process is as follows: Training data: Given a training data set Among them, x i is the input feature, y i is the target value.

[0095] Covariance matrix calculation: Construct the covariance matrix KKK of the training data: K ij =K(x i , x j ) Prediction point distribution: For the test point x * , calculate its predicted mean and variance: Among them, k * is the covariance vector between the test point and the training point, is the noise term, which represents the variance of the measurement error.

[0096] In the present invention, the detection of abnormal behavior is achieved by the following formula: Among them, A t is the anomaly score, which indicates the degree of deviation of the traffic characteristics in time window t. t >θ (set the threshold to θ), the traffic characteristics of the time window are marked as abnormal.

[0097] It should be understood that the setting of θ can be adjusted according to the false positive and false negative rate requirements of the actual environment. For example, in a high security requirement scenario, a smaller threshold can be selected to improve the detection sensitivity.

[0098] As an extension, the present invention can also combine dynamic time series models to perform multi-scale verification of anomaly detection. For example, by modeling the feature time series through ARIMA, it is further verified whether the anomalies detected by the Gaussian process are long-term.

[0099] For example, in a certain experimental environment, the present invention detected an abnormal pattern of a type of HTTP traffic by extracting packet size distribution and traffic rate characteristics using Gaussian process. The traffic characteristics showed continuous high-frequency transmission of small packets, which was further verified to be the behavior of an unknown mutant virus.

[0100] Through the above method, step S2 discloses the complete technical process from traffic feature extraction to anomaly detection. The present invention can accurately capture abnormal patterns in traffic and provide a reliable input basis for subsequent infection modeling and propagation prediction.

[0101] In this embodiment, in order to further quantify the infection risk of the device in step S3, based on the abnormal detection results extracted in step S2, the present invention constructs a dynamic infection model to describe the changes of the device infection state over time. The model combines stochastic differential equations and Bayesian inference methods to dynamically model the infection state of the device, evaluate its infection risk, and provide necessary input data for subsequent propagation trend prediction.

[0102] It should be noted that the implementation of this step is closely dependent on the accuracy of anomaly detection. Through the dynamic model, it is possible to capture the changing trend of the infection status in the time series and assess the potential risk of virus transmission.

[0103] In this embodiment, the infection state of the device is defined as a random variable S i (t) represents the infection probability of device i at time t, and its value range is [0,1]. The dynamic evolution of the infection state of the device is affected by the following factors:

[0104] The anomaly score A detected in the previous period t ;

[0105] Propagation threats from other devices during network interactions;

[0106] The randomness of virus characteristics and the self-recovery ability of the device.

[0107] The changing process of infection status can be expressed by the following formula: dS i =βS i (1-S i )dt+σS i dW t Among them, S i (t) is the infection probability of device i at time t, β is the virus transmission rate, which indicates the speed at which the virus spreads between devices, σ is the noise intensity, which reflects the impact of random disturbances on the infection state, and dW t is the Brownian motion term, which is used to model the randomness of the virus propagation process.

[0108] It should be noted that this formula is based on stochastic differential equation modeling and can accurately describe the nonlinear changes in the infection status.

[0109] Specifically, the infection state model is solved by using numerical methods, such as the Euler-Maruyama method, to discretize the continuous stochastic differential equation for easy calculation. The discretized formula is as follows: Among them, Δt is the time step, ξ~N(0,1) is a random variable obeying the standard normal distribution, which is used to simulate random disturbances.

[0110] It should be noted that the above method can effectively capture the dynamic evolution of the device infection status and is highly robust to the randomness of virus propagation.

[0111] As an option, the present invention can also be combined with the Bayesian inference method to correct the infection risk.

[0112] A t , the update formula of device infection probability is: Among them, P(S i |A t ) is the given anomaly detection result A t The infection probability of device i at this time, P(A t |S i ) is the device infection status S i The distribution of anomaly scores can be fitted through historical data, P(S i ) is the prior probability of infection state, and the initial value is set according to the background risk of network equipment. t ) is a normalization factor used to ensure that the sum of probabilities is 1.

[0113] Through Bayesian updating, the accuracy of infection risk assessment can be further improved and the output of the infection status model can be corrected.

[0114] In a possible implementation, the initialization of the infection state model can be set according to the following rules: For devices with anomaly scores higher than a threshold, the infection probability is initialized to a higher value, such as S i (0) = 0.8; for devices without obvious abnormalities, set a lower infection probability, such as S i (0) = 0.1;

[0115] For devices in critical network locations, their prior risks can be appropriately increased. This initialization method can effectively combine network topology information and anomaly detection results to further optimize the dynamic modeling of infection status.

[0116] It should be understood that the infection status dynamic model of the present invention can: dynamically capture the changing trend of the device infection status; comprehensively consider the randomness of virus transmission, the device's self-recovery ability and external transmission threats; and further improve the accuracy of infection risk assessment by combining Bayesian inference.

[0117] Through the implementation of this embodiment, the dynamic model of device infection status provides a real-time and accurate infection risk assessment tool for the present invention, laying a key foundation for subsequent steps (such as propagation trend prediction and warning generation).

[0118] In this embodiment, for step S4, in order to simulate the virus transmission path and accurately predict the diffusion trend, the present invention constructs a device interaction transmission graph model and describes the virus diffusion process in combination with the transmission dynamics equation. The transmission graph model intuitively describes the potential path of virus transmission by abstracting network devices and their interactive relationships; the transmission dynamics uses mathematical equations to simulate the spatiotemporal evolution characteristics of virus transmission, providing key support for subsequent warning generation.

[0119] It should be noted that step S4 is based on the dynamic modeling result of the infection status in step S3, takes the device infection probability as the initial condition, combines the device interaction relationship and network topology, further constructs a propagation graph model and performs diffusion simulation.

[0120] In this embodiment, the propagation graph model adopts the form of a weighted directed graph, which is expressed as: in, E is a device set, which represents all devices in the network, such as terminal devices, servers, switches, etc. t is the set of communication edges at time t, representing the communication relationship between devices, w ij (t) is the transmission potential between them.

[0121] It should be noted that the weight w in the propagation graph model ij (t) is determined by the communication frequency and traffic statistics between devices. The specific calculation formula is: Among them, C ij (t) is the number of communications within time t, ∑ k C ik (t) is the total number of communications with all other devices.

[0122] Specifically, the edge weight w of the propagation graph model ij (t) will change dynamically over time. For example, when the frequency of interaction between devices increases within a certain period of time, the weight will increase, reflecting that the virus is more likely to spread through this path.

[0123] In a possible implementation, the initial construction of the propagation graph model can be achieved through the following steps:

[0124] Node initialization: Generate a node set based on the device list in the network topology , and assign each node an initial infection probability I(v, 0), which comes from the infection state model in step S3.

[0125] Edge set generation: Extract the communication relationship between devices based on the network traffic log and generate the edge set E t ;

[0126] Weight calculation: Use the above formula to calculate the weight w of each edge ij (t).

[0127] It should be noted that the dynamics of the transmission graph model can reflect the evolution of the virus transmission path over time, providing a reliable basis for the simulation of subsequent diffusion trends.

[0128] In this embodiment, the propagation graph model combines the propagation dynamics equation to simulate the virus diffusion process. Specifically, for each node in the propagation graph , define its infection probability as l(v, t), and the uninfected state as S(v, t) = 1-l(v, t). The propagation dynamics equation describes the change of the node infection state over time, and the formula is as follows:

[0129]

[0130] in, For Node The infection probability change rate at time t indicates the changing trend of the infection status over time. N(v) is the node The set of adjacent nodes, β uv (t) is edge e uv The propagation rate of the virus from the node Propagate to nodes The probability of l(u, t) is the adjacent node The infection probability of node The current ability to spread the virus, γ is the recovery rate, which indicates the rate at which the device recovers from the infected state to the healthy state.

[0131] It should be noted that the transmission rate β uv (t) and edge weight w uv (t) is related to the virus characteristics and is defined as follows: β uv (t) = w uv (t)·λwhere w uv (t) is edge e uv The weight comes from the propagation graph model, and λ is the virus transmission capability parameter obtained by experimental calibration.

[0132] Weight w uv (t) reflects the importance of communication between devices, and the virus characteristic parameter λ reflects the attack capability of the virus. Different virus characteristics and network topologies will lead to differences in propagation rates. This formula provides scalability for propagation dynamics.

[0133] In one possible implementation, the propagation dynamics equation is solved using a numerical discretization method to facilitate propagation simulation under limited computing resources. The discretized formula is:

[0134]

[0135] Among them, l(v, t+Δt) is the node The infection probability at time t+Δt, Δt is the time step, indicating the time granularity of the simulation.

[0136] This formula discretizes the transmission dynamics equation and converts the continuous time-changing process into discrete time step updates. It is suitable for computer simulation. In each time step, the update of the infection probability is determined by the infection status and transmission rate of the previous time step, which can dynamically reflect the evolution of virus transmission.

[0137] As an extension, the present invention supports dynamic weight adjustment in the propagation graph model to adapt to changes in network traffic. For example, the communication frequency between devices may change significantly over time, thereby affecting the virus propagation path. The dynamic weight adjustment formula is:

[0138]

[0139] Among them, C ij For device v i and v j The communication statistics at time t, α is the adjustment rate parameter, which indicates the sensitivity of the weight to communication changes. The formula dynamically adjusts the weight w according to the change of the communication frequency between devices. ij (t), the propagation graph model can reflect the real-time changes of network traffic, and the dynamic adjustment mechanism improves the accuracy and real-time performance of propagation dynamics simulation.

[0140] It is important to understand that the propagation graph model and propagation dynamics simulation have significant advantages in the following aspects:

[0141] Accurately reflect the network topology and device interaction relationship, simulate the virus propagation path and time dynamic characteristics, support dynamic weight adjustment mechanism, and adapt to changes in the network environment.

[0142] Through the implementation of the present invention, the accuracy and real-time performance of virus propagation prediction are significantly improved, laying a foundation for the optimization of subsequent early warning and defense strategies.

[0143] In this embodiment, for step S5, in order to achieve real-time early warning and effective defense against virus transmission, the present invention generates early warning information and optimizes defense strategies based on the results of propagation trend prediction. By analyzing the virus's diffusion path, infection scope and impact, the early warning level is dynamically adjusted, and priority defense measures are formulated for key nodes to achieve the effects of rapid response and resource optimization.

[0144] It should be noted that step S5 is based on the aforementioned propagation graph model and dynamic simulation, and further combines risk assessment and optimization theory to form a complete early warning and defense strategy output mechanism.

[0145] In this embodiment, the early warning information is based on a comprehensive assessment of the probability of device infection and the spread trend. To this end, the risk index R(v, t) is introduced to quantify the risk level of each node, which is defined as follows: R(v, t) = P(v) l(v, t) where R(v, t) is the risk value of node v at time t, P(v) is the weight factor of the node, reflecting the importance of the node, for example, the server node has a higher weight than the terminal node, and l(v, t) is the infection probability of node v, which is calculated by the propagation dynamics equation.

[0146] The risk index R(v, t) indicates the potential threat level of the device in the current infection state. Nodes with high risk values ​​are given priority in the early warning range. By setting the weight factor P(v), the security requirements of different types of network devices can be flexibly adapted.

[0147] As an option, you can divide the warning levels according to the size of the risk indicators:

[0148] When R(v, t)>θ1 (high risk threshold), a red warning is triggered;

[0149] When θ2<R(v, t)≤θ1 (medium risk threshold), a yellow warning is triggered;

[0150] When R(v, t)≤θ2 (low risk threshold), no warning is triggered

[0151] It should be noted that the above thresholds θ1 and θ2 can be adjusted according to specific scenarios to balance the ratio of false positives to false negatives.

[0152] In this embodiment, the defense optimization information is generated. Specifically, the defense optimization information dynamically optimizes defense measures by building a key node priority model and combining resource allocation strategies. To this end, the key node priority is defined as:

[0153]

[0154] Where K(v, t) is the criticality of node v at time t, α and β are weight parameters, indicating the relative importance of risk index and adjacent node propagation contribution, and w uv (t) is the adjacent node propagation weight, calculated by the propagation graph model, l(u, t) is the infection probability of the adjacent node u, the node criticality K(v, t) comprehensively considers its own risk, R(v, t) is the propagation contribution with adjacent nodes, and nodes with higher criticality are preferentially allocated defense resources. By adjusting the parameters α and β, a trade-off can be made between local protection and global propagation control.

[0155] In one possible implementation, resource optimization allocation is based on the optimal strategy framework in game theory, aiming to minimize the scope of virus propagation. Assuming that the total amount of defense resources is limited and the allocation goal is to optimally cover the set of highly critical nodes, the resource allocation problem can be expressed as: Constraints: x V ∈{0,1}where x V Whether the node V is allocated resources, 1 means allocated, 0 means unallocated, R total is the total amount of available defense resources. The goal of this optimization problem is to give priority to protecting nodes with higher criticality. At the same time, it is limited by the total resource constraints. By solving it through the linear programming method, the resource allocation strategy x for each node can be determined. V .

[0156] As an option, the present invention also supports a dynamic adjustment mechanism based on the propagation trend. For example, when the propagation trend shows that the probability of infection is concentrated in a certain subnet, resources can be preferentially allocated to high-criticality nodes in the subnet.

[0157] The dynamic adjustment formula is:

[0158]

[0159] Among them, K′(v, t) is the adjusted criticality, and γ is the adjustment parameter that controls the weight of local node criticality and neighborhood propagation contribution.

[0160] It should be understood that the present invention generates warning and defense optimization information through step S5, which has the following significant advantages: the risk assessment model combines infection probability and node importance to accurately identify high-risk devices;

[0161] Defense optimization strategies are based on game theory and linear programming to ensure optimal allocation of limited resources;

[0162] The dynamic adjustment mechanism adapts to changes in propagation trends and improves the effectiveness of defense measures.

[0163] Through the above detailed implementation, step S5 constitutes the core link of the virus propagation warning and defense system, providing comprehensive technical support for network security management.

[0164] Please see attached Figure 2 ,A virus monitoring and early warning system based on deep analysis of network traffic, the system includes:

[0165] Traffic collection module, used to collect traffic data and extract traffic features through deep packets;

[0166] Anomaly detection module, used to detect abnormal behavior in traffic based on Gaussian process model;

[0167] The infection risk assessment module is used to describe the dynamic evolution of the device infection state using stochastic differential equations;

[0168] The transmission trend prediction module is used to construct a transmission map and simulate the virus's transmission path;

[0169] The early warning and defense module is used to generate early warning information and optimize defense strategies based on game theory.

[0170] Among them, the traffic collection module: This module is used to collect network traffic data in real time through deep packet inspection technology, and extract key traffic features such as packet size, traffic rate and protocol distribution, providing basic data input for subsequent anomaly detection and risk assessment.

[0171] Anomaly detection module: This module models the traffic feature sequence based on the Gaussian process model, analyzes the distribution characteristics of normal traffic behavior, detects abnormal patterns that deviate from normal behavior, and thus identifies potential virus threats.

[0172] Infection risk assessment module: This module describes the dynamic evolution of the device infection state through stochastic differential equations, quantifies the infection risk of the device based on the anomaly detection results, outputs the infection probability of the device at different times, and provides input for transmission prediction.

[0173] Propagation trend prediction module: This module constructs a propagation graph model of device interaction and combines it with the propagation dynamics equation to simulate the virus's propagation path and trend in the network, predicts the possible spread and impact of the virus, and provides support for the generation of defense strategies.

[0174] Early warning and defense module: This module generates graded early warning information based on the results of propagation trend prediction, and optimizes the allocation strategy of defense resources through game theory and linear programming, giving priority to protecting high-criticality nodes, inhibiting the spread of the virus, and achieving efficient early warning and defense functions.

[0175] The present invention provides a virus monitoring and early warning method based on deep analysis of network traffic. It extracts traffic features through deep packet detection and establishes an anomaly detection model to identify abnormal patterns that deviate from normal behavior. It quantifies the infection risk by combining dynamic modeling of the device infection status. It simulates the virus diffusion path and trend in the network by constructing a device interaction propagation graph model and a propagation dynamics equation. Finally, it generates early warning information based on the propagation prediction results and dynamically optimizes the defense strategy, thereby realizing accurate monitoring of unknown viruses and mutant viruses, propagation trend prediction and efficient defense, and providing a real-time, intelligent and scalable solution for virus protection in complex network environments.

[0176] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A virus monitoring and early warning method based on deep analysis of network traffic, characterized in that: The following steps are involved: Use deep packet inspection technology to collect traffic data in real time, extract traffic features, and divide them into traffic feature sequences based on time windows; An abnormal behavior detection model is established based on the traffic feature sequence to detect abnormal patterns in traffic that deviate from the normal behavior distribution; According to the abnormal behavior detection results, a dynamic model of the device infection status is established to conduct infection risk assessment, including: device infection status S i (t) is described by the following differential equation: dS i =βS i (1-S i (dt+σS i dW t , Among them, S i (t) is the infection probability of device i at time t, β is the propagation rate, σ is the noise intensity, dW t is Brownian motion; by numerically solving the differential equation, the infection probability S of the device at a future time point is predicted i (t+Δt), Δt is the time step; Build a propagation graph model of device interaction based on propagation dynamics to simulate the prediction of virus propagation trends in the network; Generate early warning and defense optimization information based on the propagation trend prediction results.

2. The virus monitoring and early warning method based on network traffic in-depth analysis according to claim 1 is characterized in that: The flow data collection comprises the following steps: Extract the traffic characteristics of data packets in the network through deep packet inspection technology: The traffic data is divided using the time window mechanism, the features within the time window are extracted as feature vectors, and the traffic feature matrix is ​​generated.

3. The virus monitoring and early warning method based on network traffic in-depth analysis according to claim 1 is characterized in that: The abnormal behavior detection comprises the following steps: Based on the Gaussian process model, the normal behavior of traffic characteristics is modeled and a traffic prediction model is established; By calculating the deviation of traffic characteristics, anomaly scores are generated and abnormal behavior is detected.

4. The virus monitoring and early warning method based on network traffic in-depth analysis according to claim 1 is characterized in that: The propagation trend prediction comprises the following steps: Construct a propagation graph model and assign weights to represent communication strength; Based on the infection status and propagation path of the device, the propagation dynamics model is used to predict the spread and trend of the virus in the network.

5. The virus monitoring and early warning method based on network traffic in-depth analysis according to claim 1 is characterized in that: The early warning and defense optimization includes the following steps: Calculate the infection risk index based on the device infection probability and the device importance weight; Generate early warning information based on infection risk indicators, including identification of high-risk devices and prediction of virus transmission paths; Optimize defense strategies based on game theory, dynamically adjust defense resource allocation, prioritize protection of key equipment, and prevent virus spread.

6. The virus monitoring and early warning method based on network traffic in-depth analysis according to claim 5 is characterized in that: The defense optimization constructs an adversarial game model, in which the attacker spreads the virus by selecting key device nodes, and the defender suppresses the virus propagation by selecting and protecting key device nodes, thereby solving the optimal defense strategy to reduce network propagation.

7. The virus monitoring and early warning method based on network traffic in-depth analysis according to claim 6 is characterized in that: In the defense optimization step, the defense strategy protects devices with high propagation criticality by dynamically adjusting the defense priority according to the propagation criticality of the devices.

8. The virus monitoring and early warning method based on network traffic in-depth analysis according to claim 4 is characterized in that: The propagation graph model is expressed by the following formula: t =(v, E t )in, v is the device set, E t is the set of communication edges at time t.

9. A virus monitoring and early warning system based on deep analysis of network traffic, applied to the virus monitoring and early warning method based on deep analysis of network traffic as claimed in any one of claims 1 to 8, characterized in that: The system includes: Traffic collection module, used to collect traffic data and extract traffic features through deep packets; Anomaly detection module, used to detect abnormal behavior in traffic based on Gaussian process model; The infection risk assessment module is used to describe the dynamic evolution of the device infection state using stochastic differential equations, and also includes: the device infection state S i (t) is described by the following differential equation: dS i =βS i (1-S i )dt+σS i dW t , Among them, S i (t) is the infection probability of device i at time t, β is the propagation rate, σ is the noise intensity, dW t is Brownian motion; by numerically solving the differential equation, the infection probability S of the device at a future time point is predicted i (t+Δt), Δt is the time step; The transmission trend prediction module is used to construct a transmission map and simulate the virus's transmission path; The early warning and defense module is used to generate early warning information and optimize defense strategies based on game theory.

Citation Information

Patent Citations

  • Inhibition method and system for social network virus information

    CN108092832A

  • Network attack risk control method and system based on game theory

    CN110138778A

  • Abnormal traffic detection method and related equipment

    CN119011190A