A Network Abnormal Transmission Identification and Blocking Method and System Based on Data Mining

By preprocessing and analyzing real-time network traffic data, identifying and blocking network abnormal traffic types, the problem of inability to effectively identify and block network abnormal traffic in the prior art is solved, and intelligent identification and precise blocking of network security are achieved.

CN119584129BActive Publication Date: 2025-06-03SUZHOU GUANGLIAN COMMUNICATION TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411819150.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-11
Publication Date
2025-06-03
Estimated Expiration
2044-12-11

AI Technical Summary

Technical Problem

The prior art cannot effectively identify and block the types of abnormal traffic in the network, and it is difficult to ensure the precise blocking of abnormal data flows.

Method used

By pre-processing the real-time network traffic data, real-time network traffic characteristic data is generated, and real-time analysis and processing is carried out with the characteristic data of different network abnormal traffic types to identify abnormal traffic types. Then, search based on the spatial location data of the blocking node, determine the blocking node, and finally build real-time network abnormal traffic identification data and perform blocking jobs.

Benefits of technology

It realizes intelligent identification and precise blocking of abnormal network traffic, improving the stability and reliability of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119584129B_ABST
    Figure CN119584129B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of wireless network communication technology, and specifically provides a method and system for identifying and blocking network abnormal transmissions based on data mining. By preprocessing the collected real-time network traffic data, real-time network traffic feature data is generated, and real-time network abnormal traffic type analysis and processing are performed with the established feature data of different network abnormal traffic types to generate real-time network traffic analysis data. If the real-time network traffic analysis data is normal, the current network traffic identification task is ended; if the real-time network traffic analysis data is abnormal, real-time network abnormal traffic type feature data is generated, and blocking node spatial location search processing is performed with the established network abnormal traffic type blocking node spatial location data to obtain real-time network abnormal traffic blocking node spatial location data. Finally, real-time network abnormal traffic identification data is constructed, and real-time network abnormal traffic blocking operations are executed to achieve intelligent identification and precise blocking of network abnormal traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of wireless network communication, and specifically to a method and system for identifying and blocking network abnormal transmissions based on data mining. Background Art

[0002] During network transmission, network abnormal traffic refers to network traffic data that deviates from normal network behavior. With the continuous development of Internet technology, diverse network environments and services bring convenience to people, while more complex network traffic also poses greater and more severe challenges to network security.

[0003] The Chinese patent application with the publication number CN106330964A introduces a network intrusion detection and active defense linkage control device. By combining the traditional network anomaly detection PHAD model method to deeply detect and analyze the key fields of the data packet content, it accurately determines whether the network traffic is aggressive, and realizes the blocking of abnormal data traffic by dynamically intervening in the forwarding rule table of the data packet forwarding module, achieving the active truncation of abnormal data streams and the linkage effect of active detection and active defense of attacks. However, it cannot further analyze and identify the types of network abnormal traffic, and at the same time, it does not analyze the blocking nodes of abnormal data streams, making it difficult to ensure the accurate blocking of abnormal data streams. Summary of the Invention

[0004] To solve the deficiencies in the background art, the present invention provides a method and system for identifying and blocking network abnormal transmissions based on data mining, realizing the intelligent identification and accurate blocking of network abnormal traffic.

[0005] A method for identifying and blocking network abnormal transmissions based on data mining includes the following steps:

[0006] S1. Collect real-time network traffic data;

[0007] S2. Perform data preprocessing on the real-time network traffic data to generate real-time network traffic feature data;

[0008] S3. Establish feature data of different network abnormal traffic types;

[0009] S4. Perform real-time network abnormal traffic type analysis and processing based on the real-time network traffic feature data and the feature data of different network abnormal traffic types to generate real-time network traffic analysis data. If the real-time network traffic analysis data is normal, end the current network traffic identification task; if the real-time network traffic analysis data is abnormal, generate real-time network abnormal traffic type feature data;

[0010] S5. Establish spatial location data of network abnormal traffic type blocking nodes;

[0011] S6. Perform a blocking node spatial location search process based on the blocked node spatial location data of the network abnormal traffic type and the real-time network abnormal traffic type feature data to obtain the real-time network abnormal traffic blocked node spatial location data;

[0012] S7. Construct real-time network abnormal traffic identification data based on the real-time network traffic analysis data, the real-time network abnormal traffic type feature data, and the real-time network abnormal traffic blocked node spatial location data, and perform a real-time network abnormal traffic blocking operation.

[0013] Through data preprocessing of the collected real-time network traffic data, the present invention generates real-time network traffic feature data, and performs real-time network abnormal traffic type analysis processing with the established different network abnormal traffic type feature data to generate real-time network traffic analysis data. If the real-time network traffic analysis data is normal, the current network traffic identification operation is ended; if the real-time network traffic analysis data is abnormal, real-time network abnormal traffic type feature data is generated, and a blocking node spatial location search process is performed with the established network abnormal traffic type blocked node spatial location data to obtain the real-time network abnormal traffic blocked node spatial location data. Finally, real-time network abnormal traffic identification data is constructed, and a real-time network abnormal traffic blocking operation is performed to realize the intelligent identification and precise blocking of network abnormal traffic.

[0014] Preferably, the specific steps for collecting real-time network traffic data are as follows:

[0015] S11. Timely collect the network traffic data of each passing node through the network traffic data collection unit to generate a real-time network traffic data set A = {a 1 , a 2 , …, a i , …, a k}, where a i represents the network traffic data of the i-th passing node collected in real time by the network traffic data collection unit, k represents the total number of nodes through which the network traffic data passes, the network traffic data includes but is not limited to the source IP address, destination IP address, packet information, protocol information, traffic transmission rate, and traffic distribution, and the nodes through which the network abnormal traffic passes include but are not limited to core routers, switches, firewalls, and important servers.

[0016] Preferably, the specific steps for performing data preprocessing on the real-time network traffic data to generate real-time network traffic feature data are as follows:

[0017] S21. Perform network traffic data noise reduction processing on the real-time network traffic data in the real-time network traffic data set through a bilateral filtering algorithm to generate a real-time network traffic feature data set , where represents the real-time network traffic feature data obtained after performing network traffic data noise reduction processing on the i-th real-time network traffic data in the real-time network traffic dataset;

[0018] The network traffic data noise reduction processing of the real-time network traffic data in the real-time network traffic dataset by the bilateral filtering algorithm includes the following steps:

[0019] S211. Select the real-time network traffic data in the real-time network traffic dataset as the target sample data;

[0020] S212. Perform network traffic data noise reduction processing on the target sample data using the bilateral filtering noise reduction formula; the bilateral filtering noise reduction formula is as follows:

[0021] ,

[0022] where f(x) represents the target sample data after network traffic data noise reduction processing, f(y) represents the target sample data before network traffic data noise reduction processing, Ω(x) represents the neighborhood search area centered on the sample point x in the target sample data, and W(x, y) represents the bilateral filtering kernel coefficient;

[0023] S213. Repeat the operations in S211 to S212 until all the real-time network traffic data in the real-time network traffic dataset are traversed, and then generate a real-time network traffic feature dataset.

[0024] By performing network traffic data noise reduction processing on the real-time network traffic data through the bilateral filtering algorithm, the noise data in the real-time network traffic data are accurately identified and removed, effectively reducing the influence brought by the noise data in the real-time network traffic data, ensuring the reliability of the obtained data, and at the same time better highlighting the detail features in the real-time network traffic data.

[0025] Preferably, the specific steps for establishing the feature data of different network abnormal traffic types are as follows:

[0026] S31. Establish a feature dataset B = {b 1 , b 2 , …, b i , …, b l} of different network abnormal traffic types, where b i represents the network traffic feature data of each node passed when the i-th network abnormal traffic type appears, l represents the total number of the feature data of different network abnormal traffic types, and the network abnormal traffic types include but are not limited to network traffic distribution anomalies, network traffic transmission rate anomalies, network traffic address anomalies, network attack anomalies, and protocol information anomalies.

[0027] Preferably, real-time network abnormal traffic type analysis and processing are performed based on the real-time network traffic characteristic data and the different network abnormal traffic type characteristic data to generate real-time network traffic analysis data. If the real-time network traffic analysis data is normal, this network traffic identification operation is ended; if the real-time network traffic analysis data is abnormal, the specific steps for generating real-time network abnormal traffic type characteristic data are as follows:

[0028] S41. Perform real-time network abnormal traffic type analysis and processing on each different network abnormal traffic type characteristic data in the real-time network abnormal traffic characteristic data set and the different network abnormal traffic type characteristic data set through the firefly optimization algorithm, and generate real-time network traffic analysis data Q according to the real-time network abnormal traffic type analysis result fenxi , if the real-time network traffic analysis data Q fenxi is normal, this network traffic identification operation is ended; if the real-time network traffic analysis data Q fenxi is abnormal, real-time network abnormal traffic type characteristic data C is generated leixing ;

[0029] S411. Construct a firefly population, set the firefly population size as N, the light intensity absorption coefficient as γ, the step size perturbation factor as α, the current iteration number as t, the maximum iteration number as t max and the search space dimension of different network abnormal traffic type characteristic data as P;

[0030] Randomly generate N different network abnormal traffic type characteristic data in the search space of the different network abnormal traffic type characteristic data. Each different network abnormal traffic type characteristic data corresponds to a firefly individual in the firefly population, and initialize the initial position set of the firefly population as X = {X 1 , X 2 , …, X i , …, X N}, where X i represents the initial position of the i-th firefly individual in the firefly population;

[0031] S412. Calculate the luminous brightness of each firefly individual in the firefly population, arrange each firefly individual in the firefly population in descending order of luminous brightness, and select the firefly individual with the highest luminous brightness as the current optimal individual; the luminous brightness calculation formula is as follows:

[0032] ,

[0033] where, I i represents the luminous brightness of the i-th firefly individual in the firefly population, xi represents the matching degree between the characteristic data of the i-th firefly individual in the firefly population corresponding to different network abnormal traffic types and the real-time network traffic characteristic data; represents the correction value;

[0034] S413. Calculate the spatial distance between each firefly individual in the firefly population; the spatial distance calculation formula is as follows:

[0035] ,

[0036] where d i,j represents the spatial distance between the i-th firefly individual and the j-th firefly individual in the firefly population, and X i,z and X j,z respectively represent the positions of the i-th firefly individual and the j-th firefly individual in the search space of the characteristic data of different network abnormal traffic types in the z-th dimension in the firefly population;

[0037] S414. Calculate the relative attraction degree between each firefly individual in the firefly population according to the spatial distance between each firefly individual in the firefly population; the relative attraction degree calculation formula is as follows:

[0038] ,

[0039] where β i,j represents the relative attraction degree between the i-th firefly individual and the j-th firefly individual in the firefly population, and β 0 represents the attraction degree when the distance between any two firefly individuals in the firefly population is 0;

[0040] S415. Each firefly individual in the firefly population will be attracted by the firefly individual with higher luminous brightness in the search space of the characteristic data of different network abnormal traffic types for position update; the position update formula is as follows:

[0041] ,

[0042] where represents the position of the i-th firefly individual in the firefly population after position update, and respectively represent the positions of the i-th firefly individual and the j-th firefly individual in the t-th iteration process in the firefly population, and rand represents a random number uniformly distributed between (0, 1);

[0043] The current optimal individual in the firefly population is updated by random walk in the search space of the characteristic data of different network abnormal traffic types;

[0044] S416. Calculate the luminous intensity of each firefly individual in the firefly population after position update in the search space of the different network abnormal traffic type characteristic data. If the luminous intensity of the firefly individual after position update is greater than that of the original position, replace the original position with the new position; otherwise, retain the original position.

[0045] S417. If the luminous intensity of a firefly individual in the search space of the different network abnormal traffic type characteristic data is greater than that of the current optimal individual, then take this firefly individual as the new current optimal individual; otherwise, directly proceed to S418.

[0046] S418. Determine whether the current iteration number t is less than the maximum iteration number t max , if the current iteration number t is less than the maximum iteration number t max , then increment the current iteration number t by 1 and return to S413; otherwise, take the current optimal individual as the global optimal solution.

[0047] S419. Set the fitness function threshold. If the fitness function value of the global optimal solution is less than or equal to the fitness function threshold, it indicates that the real-time network environment is in a safe state, and output the real-time network traffic analysis data Q fenxi as normal; if the fitness function value of the global optimal solution is greater than the fitness function threshold, it indicates that the real-time network environment is in a dangerous state, output the real-time network traffic analysis data Q fenxi as abnormal, and identify the different network abnormal traffic type characteristic data corresponding to the global optimal solution and generate the real-time network abnormal traffic type characteristic data C leixing .

[0048] Perform real-time network abnormal traffic type analysis and processing on the real-time network abnormal traffic characteristic data and the different network abnormal traffic type characteristic data through the firefly optimization algorithm, realize the scientific analysis of the real-time network abnormal traffic type, accurately identify the type of the real-time network abnormal traffic. At the same time, the firefly optimization algorithm has good robustness, which can ensure the stability and reliability of the analysis process.

[0049] Preferably, the specific steps for establishing the spatial position data of the network abnormal traffic type blocking node are as follows:

[0050] S51. Preset the corresponding blocking node spatial position data for the different network abnormal traffic type characteristic data in the different network abnormal traffic type characteristic data set through the network traffic blocking node data storage unit, and generate the network abnormal traffic type blocking node spatial position data set D = {d 1 , d 2 , …, di ,…,d l}, where d i represents the blocked node spatial location data corresponding to the i-th network abnormal traffic type.

[0051] Preferably, the specific steps for performing blocked node spatial location search processing based on the blocked node spatial location data of the network abnormal traffic type and the real-time network abnormal traffic type characteristic data to obtain the blocked node spatial location data of the real-time network abnormal traffic are as follows:

[0052] S61. Use the breadth-first search algorithm to perform blocked node spatial location search processing on the real-time network abnormal traffic type characteristic data C leixing and the blocked node spatial location data of the network abnormal traffic type in the blocked node spatial location data set of the network abnormal traffic type, traverse all the blocked node spatial location data of the network abnormal traffic type in the blocked node spatial location data set of the network abnormal traffic type, search for the blocked node spatial location data of the network abnormal traffic type that matches the real-time network abnormal traffic type characteristic data C leixing and perform data identification to generate the blocked node spatial location data E shishi of the real-time network abnormal traffic.

[0053] Use the breadth-first search algorithm to perform blocked node spatial location search processing on the real-time network abnormal traffic type characteristic data and the blocked node spatial location data of the network abnormal traffic type, search for the data that matches the current situation from the preset blocked node spatial location data, provide a data basis for abnormal traffic blocking and interception, and ensure the accuracy of the implementation of the real-time network abnormal traffic blocking operation.

[0054] Preferably, the specific steps for constructing real-time network abnormal traffic identification data based on the real-time network traffic analysis data, the real-time network abnormal traffic type characteristic data, and the real-time network abnormal traffic blocked node spatial location data and performing real-time network abnormal traffic blocking operations are as follows:

[0055] S71. Combine the real-time network traffic analysis data Q fenxi , the real-time network abnormal traffic type characteristic data C leixing and the real-time network abnormal traffic blocked node spatial location data E shishi to construct the real-time network abnormal traffic identification data F = (Q fenxi , C leixing , E shishi );

[0056] S72. Transmit the real-time network abnormal traffic identification data F = (Qfenxi , C leixing , E shishi ) Push it to the network abnormal traffic identification and blocking platform and perform real-time network abnormal traffic blocking operations.

[0057] The present invention also discloses a network abnormal transmission identification and blocking system based on data mining, including a real-time network traffic data acquisition module, a real-time network traffic data preprocessing module, a different network abnormal traffic type feature data establishment module, a real-time network abnormal traffic type analysis module, a network abnormal traffic type blocking node spatial position data preset module, a real-time network abnormal traffic blocking node spatial position search module, and a real-time network abnormal traffic identification data construction module;

[0058] The real-time network traffic data acquisition module regularly collects real-time network traffic data of each passing node through the network traffic data acquisition unit to generate real-time network traffic data;

[0059] The real-time network traffic data preprocessing module performs network traffic data noise reduction processing on the real-time network traffic data in the real-time network traffic data set through the bilateral filtering algorithm to generate real-time network traffic feature data;

[0060] The different network abnormal traffic type feature data establishment module establishes different network abnormal traffic type feature data;

[0061] The real-time network abnormal traffic type analysis module performs real-time network abnormal traffic type analysis processing on the real-time network traffic feature data and the different network abnormal traffic type feature data through the firefly optimization algorithm to generate real-time network traffic analysis data. If the real-time network traffic analysis data is normal, the current network traffic identification operation ends; if the real-time network traffic analysis data is abnormal, real-time network abnormal traffic type feature data is generated;

[0062] The network abnormal traffic type blocking node spatial position data preset module presets corresponding blocking node spatial position data for the different network abnormal traffic type feature data through the network traffic blocking node data storage unit to generate network abnormal traffic type blocking node spatial position data;

[0063] The real-time network abnormal traffic blocking node spatial position search module performs blocking node spatial position search processing on the network abnormal traffic type blocking node spatial position data and the real-time network abnormal traffic type feature data through the breadth-first search algorithm to obtain real-time network abnormal traffic blocking node spatial position data;

[0064] The real-time network abnormal traffic recognition data construction module combines the real-time network traffic analysis data, the real-time network abnormal traffic type feature data, and the real-time network abnormal traffic blocking node spatial location data to construct real-time network abnormal traffic recognition data, and pushes it to the network abnormal traffic identification and blocking platform through a wireless communication network, while performing real-time network abnormal traffic blocking operations.

[0065] Beneficial effects

[0066] 1. By preprocessing the collected real-time network traffic data, the present invention generates real-time network traffic feature data, and performs real-time network abnormal traffic type analysis processing with the established different network abnormal traffic type feature data to generate real-time network traffic analysis data. If the real-time network traffic analysis data is normal, the current network traffic recognition operation ends; if the real-time network traffic analysis data is abnormal, real-time network abnormal traffic type feature data is generated, and blocking node spatial location search processing is performed with the established network abnormal traffic type blocking node spatial location data to obtain real-time network abnormal traffic blocking node spatial location data. Finally, real-time network abnormal traffic recognition data is constructed, and real-time network abnormal traffic blocking operations are performed to achieve intelligent recognition and precise blocking of network abnormal traffic;

[0067] 2. The bilateral filtering algorithm is used to perform noise reduction processing on the real-time network traffic data, accurately identify the noise data in the real-time network traffic data and eliminate it, effectively reducing the influence brought by the noise data in the real-time network traffic data, ensuring the reliability of the obtained data, and better highlighting the detail features in the real-time network traffic data;

[0068] 3. The firefly optimization algorithm is used to perform real-time network abnormal traffic type analysis processing on the real-time network abnormal traffic feature data and the different network abnormal traffic type feature data, realizing scientific analysis of real-time network abnormal traffic types, accurately identifying the types of real-time network abnormal traffic. At the same time, the firefly optimization algorithm has good robustness, which can ensure the stability and reliability of the analysis process;

[0069] 4. The breadth-first search algorithm is used to perform blocking node spatial location search processing on the real-time network abnormal traffic type feature data and the network abnormal traffic type blocking node spatial location data, search for data that matches the current situation from the preset blocking node spatial location data, providing a data basis for abnormal traffic blocking interception, and ensuring the accuracy of the implementation of real-time network abnormal traffic blocking operations. Description of the drawings

[0070] To more clearly illustrate the technical solutions of the embodiments of the invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0071] Figure 1 It is a flowchart of a method for identifying and blocking network abnormal transmissions based on data mining provided by the present invention;

[0072] Figure 2 It is a schematic diagram of modules of a system for identifying and blocking network abnormal transmissions based on data mining provided by the present invention. Specific embodiments

[0073] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0074] In the description of the present invention, it should be understood that terms such as "opening", "upper", "lower", "top", "middle", "inner", etc. indicating orientation or position relationships are only for the convenience of describing the invention and simplifying the description, rather than indicating or implying that the components or elements referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation of the invention.

[0075] Embodiment 1 is as follows:

[0076] Please refer to Figure 1 , a method for identifying and blocking network abnormal transmissions based on data mining, including the following steps:

[0077] S1. Collect real-time network traffic data;

[0078] S11. Timely collect the network traffic data of each passing node through the network traffic data collection unit to generate a real-time network traffic data set A = {a 1 , a 2 , …, a i , …, a k}, where a irepresents the network traffic data of the \(i\)-th node passed by the network traffic data acquisition unit in real time. \(k\) represents the total number of nodes through which the network traffic data passes. The network traffic data includes but is not limited to source IP address, destination IP address, packet information, protocol information, traffic transmission rate, and traffic distribution. The nodes through which the network abnormal traffic passes include but are not limited to core routers, switches, firewalls, and important servers.

[0079] S2. Perform data preprocessing on the real-time network traffic data to generate real-time network traffic feature data;

[0080] S21. Perform network traffic data noise reduction processing on the real-time network traffic data in the real-time network traffic data set through a bilateral filtering algorithm to generate a real-time network traffic feature data set , where represents the real-time network traffic feature data obtained after performing network traffic data noise reduction processing on the \(i\)-th real-time network traffic data in the real-time network traffic data set;

[0081] The network traffic data noise reduction processing of the real-time network traffic data in the real-time network traffic data set through the bilateral filtering algorithm includes the following steps:

[0082] S211. Select the real-time network traffic data in the real-time network traffic data set as the target sample data;

[0083] S212. Perform network traffic data noise reduction processing on the target sample data using the bilateral filtering noise reduction formula; the bilateral filtering noise reduction formula is as follows:

[0084] ,

[0085] where \(f(x)\) represents the target sample data after network traffic data noise reduction processing, \(f(y)\) represents the target sample data before network traffic data noise reduction processing, \(\Omega(x)\) represents the neighborhood search area centered on the sample point \(x\) in the target sample data, and \(W(x,y)\) represents the bilateral filtering kernel coefficient;

[0086] S213. Repeat the operations in S211 to S212 until all the real-time network traffic data in the real-time network traffic data set are traversed, and then generate a real-time network traffic feature data set.

[0087] S3. Establish characteristic data of different network abnormal traffic types;

[0088] S31. Establish a characteristic data set \(B = \{b 1 ,b 2 ,…,b i ,…,b l}, where b i represents the network traffic feature data of each node passed when the i-th network abnormal traffic type appears, l represents the total number of different network abnormal traffic type feature data, and the network abnormal traffic types include but are not limited to abnormal network traffic distribution, abnormal network traffic transmission rate, abnormal network traffic address, network attack abnormality, and protocol information abnormality.

[0089] S4. Perform real-time network abnormal traffic type analysis and processing based on the real-time network traffic feature data and the different network abnormal traffic type feature data to generate real-time network traffic analysis data. If the real-time network traffic analysis data is normal, end this network traffic identification task; if the real-time network traffic analysis data is abnormal, generate real-time network abnormal traffic type feature data;

[0090] S41. Perform real-time network abnormal traffic type analysis and processing on each different network abnormal traffic type feature data in the real-time network abnormal traffic feature data set and the different network abnormal traffic type feature data set through the firefly optimization algorithm, and generate real-time network traffic analysis data Q according to the real-time network abnormal traffic type analysis result fenxi , if the real-time network traffic analysis data Q fenxi is normal, end this network traffic identification task; if the real-time network traffic analysis data Q fenxi is abnormal, generate real-time network abnormal traffic type feature data C leixing ;

[0091] S411. Construct a firefly population, set the firefly population size as N, the light intensity absorption coefficient as γ, the step size perturbation factor as α, the current iteration number as t, the maximum iteration number as t max and the search space dimension of different network abnormal traffic type feature data as P;

[0092] Randomly generate N different network abnormal traffic type feature data in the search space of the different network abnormal traffic type feature data. Each different network abnormal traffic type feature data corresponds to a firefly individual in the firefly population. Initialize the initial position set of the firefly population as X = {X 1 , X 2 , …, X i , …, X N}, where X i represents the initial position of the i-th firefly individual in the firefly population;

[0093] S412. Calculate the luminous intensity of each firefly individual in the firefly population, arrange each firefly individual in the firefly population in descending order of luminous intensity, and select the firefly individual with the highest luminous intensity as the current optimal individual. The luminous intensity calculation formula is as follows:

[0094] ,

[0095] where, I i represents the luminous intensity of the i-th firefly individual in the firefly population, and x i represents the matching degree between the characteristic data of different network abnormal traffic types corresponding to the i-th firefly individual in the firefly population and the real-time network traffic characteristic data, represents the correction value;

[0096] S413. Calculate the spatial distance between each firefly individual in the firefly population. The spatial distance calculation formula is as follows:

[0097] ,

[0098] where, d i,j represents the spatial distance between the i-th firefly individual and the j-th firefly individual in the firefly population, and X i,z and X j,z respectively represent the positions of the i-th firefly individual and the j-th firefly individual in the search space of the characteristic data of different network abnormal traffic types in the z-th dimension;

[0099] S414. Calculate the relative attraction degree between each firefly individual in the firefly population according to the spatial distance between each firefly individual. The relative attraction degree calculation formula is as follows:

[0100] ,

[0101] where, β i,j represents the relative attraction degree between the i-th firefly individual and the j-th firefly individual in the firefly population, and β 0 represents the attraction degree when the distance between any two firefly individuals in the firefly population is 0;

[0102] S415. Each firefly individual in the firefly population will be attracted by the firefly individual with higher luminous intensity in the search space of the characteristic data of different network abnormal traffic types for position update. The position update formula is as follows:

[0103] ,

[0104] where, represents the position of the \(i\)-th firefly individual in the firefly population after position update, and respectively represent the positions of the \(i\)-th firefly individual and the \(j\)-th firefly individual in the firefly population during the \(t\)-th iteration process, and rand represents a random number uniformly distributed between (0, 1);

[0105] The current optimal individual in the firefly population updates its position by random walk in the search space of different network abnormal traffic type feature data;

[0106] S416. Calculate the luminous intensity of each firefly individual in the firefly population after position update in the search space of different network abnormal traffic type feature data. If the luminous intensity of the firefly individual after position update is greater than the luminous intensity of the original position, replace the original position with the new position; otherwise, retain the original position;

[0107] S417. If there is a firefly individual in the search space of different network abnormal traffic type feature data whose luminous intensity is greater than the luminous intensity of the current optimal individual, then take this firefly individual as the new current optimal individual; otherwise, directly go to S418;

[0108] S418. Determine whether the current iteration number \(t\) is less than the maximum iteration number \(t\) max If the current iteration number \(t\) is less than the maximum iteration number \(t\) max then increment the current iteration number \(t\) by 1 and return to S413; otherwise, take the current optimal individual as the global optimal solution;

[0109] S419. Set the fitness function threshold. If the fitness function value of the global optimal solution is less than or equal to the fitness function threshold, it means that the real-time network environment is in a safe state, and output the real-time network traffic analysis data \(Q\) fenxi is normal; if the fitness function value of the global optimal solution is greater than the fitness function threshold, it means that the real-time network environment is in a dangerous state, output the real-time network traffic analysis data \(Q\) fenxi is abnormal, and identify the different network abnormal traffic type feature data corresponding to the global optimal solution and generate the real-time network abnormal traffic type feature data \(C\) leixing .

[0110] S5. Establish the spatial position data of network abnormal traffic type blocking nodes;

[0111] S51. Preset corresponding blocking node spatial location data for different network abnormal traffic type feature data in the different network abnormal traffic type feature data sets through the network traffic blocking node data storage unit, and generate a network abnormal traffic type blocking node spatial location data set D = {d 1 , d 2 , …, d i , …, d l}, where d i represents the blocking node spatial location data corresponding to the i-th network abnormal traffic type.

[0112] S6. Perform blocking node spatial location search processing according to the network abnormal traffic type blocking node spatial location data and the real-time network abnormal traffic type feature data to obtain real-time network abnormal traffic blocking node spatial location data;

[0113] S61. Perform blocking node spatial location search processing on the real-time network abnormal traffic type feature data C leixing and the network abnormal traffic type blocking node spatial location data in the network abnormal traffic type blocking node spatial location data set through the breadth-first search algorithm, traverse all the network abnormal traffic type blocking node spatial location data in the network abnormal traffic type blocking node spatial location data set, search for the network abnormal traffic type blocking node spatial location data that matches the network abnormal traffic type corresponding to the real-time network abnormal traffic type feature data C leixing and perform data identification to generate real-time network abnormal traffic blocking node spatial location data E shishi .

[0114] S7. Construct real-time network abnormal traffic identification data based on the real-time network traffic analysis data, the real-time network abnormal traffic type feature data, and the real-time network abnormal traffic blocking node spatial location data, and perform real-time network abnormal traffic blocking operations;

[0115] S71. Combine the real-time network traffic analysis data Q fenxi , the real-time network abnormal traffic type feature data C leixing , and the real-time network abnormal traffic blocking node spatial location data E shishi for data combination to construct real-time network abnormal traffic identification data F = (Q fenxi , C leixing , E shishi );

[0116] S72. Transmit the real-time network abnormal traffic identification data F = (Q fenxi , C leixing , E shishi)Push it to the network abnormal traffic identification and blocking platform and perform real-time network abnormal traffic blocking operations.

[0117] The second embodiment is as follows:

[0118] Please refer to Figure 2 , a network abnormal transmission identification and blocking system based on data mining, including a real-time network traffic data acquisition module, a real-time network traffic data preprocessing module, a feature data establishment module for different network abnormal traffic types, a real-time network abnormal traffic type analysis module, a preset module for the spatial location data of network abnormal traffic type blocking nodes, a real-time network abnormal traffic blocking node spatial location search module, and a real-time network abnormal traffic identification data construction module;

[0119] The real-time network traffic data acquisition module regularly collects the network traffic data of each passing node in real time through the network traffic data acquisition unit to generate real-time network traffic data;

[0120] The real-time network traffic data preprocessing module performs network traffic data noise reduction processing on the real-time network traffic data in the real-time network traffic data set through a bilateral filtering algorithm to generate real-time network traffic feature data;

[0121] The feature data establishment module for different network abnormal traffic types establishes feature data for different network abnormal traffic types;

[0122] The real-time network abnormal traffic type analysis module performs real-time network abnormal traffic type analysis processing on the real-time network traffic feature data and the feature data of different network abnormal traffic types through a firefly optimization algorithm to generate real-time network traffic analysis data. If the real-time network traffic analysis data is normal, the current network traffic identification operation ends; if the real-time network traffic analysis data is abnormal, real-time network abnormal traffic type feature data is generated;

[0123] The preset module for the spatial location data of network abnormal traffic type blocking nodes presets corresponding blocking node spatial location data for the feature data of different network abnormal traffic types through the network traffic blocking node data storage unit to generate network abnormal traffic type blocking node spatial location data;

[0124] The real-time network abnormal traffic blocking node spatial location search module performs blocking node spatial location search processing on the network abnormal traffic type blocking node spatial location data and the real-time network abnormal traffic type feature data through a breadth-first search algorithm to obtain real-time network abnormal traffic blocking node spatial location data;

[0125] The real-time network abnormal traffic identification data construction module combines the real-time network traffic analysis data, the real-time network abnormal traffic type feature data, and the real-time network abnormal traffic blocking node spatial location data to construct real-time network abnormal traffic identification data, and pushes it to the network abnormal traffic identification and blocking platform through a wireless communication network, and simultaneously performs real-time network abnormal traffic blocking operations.

[0126] In the description of this specification, the description with reference to terms such as "one embodiment", "example", "specific example", etc. means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0127] The preferred embodiments of the invention disclosed above are only used to help explain the invention. The preferred embodiments do not elaborate all the details, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the invention, so that those skilled in the art can well understand and utilize the invention.

Claims

1. A method for identifying and blocking abnormal network transmission based on data mining, characterized in that: The steps include: S1, collect real-time network traffic data; S2, performing data preprocessing on the real-time network traffic data to generate real-time network traffic feature data; S3. Establish characteristic data of different network abnormal traffic types; S4, performing real-time network abnormal traffic type analysis and processing according to the real-time network traffic characteristic data and the different network abnormal traffic type characteristic data, generating real-time network traffic analysis data, and if the real-time network traffic analysis data is normal, ending this network traffic identification operation; If the real-time network traffic analysis data is abnormal, then real-time network abnormal traffic type feature data is generated; The S4 comprises the following steps: S41, performing real-time network abnormal traffic type analysis on the real-time network abnormal traffic feature data set and each different network abnormal traffic type feature data in the different network abnormal traffic type feature data set by using the firefly optimization algorithm, and generating real-time network traffic analysis data Q according to the real-time network abnormal traffic type analysis result. fenxi , if the real-time network traffic analysis data Q fenxi If the real-time network traffic analysis data Q fenxi If it is abnormal, the real-time network abnormal traffic type feature data C is generated. leixing; The S41 comprises the following steps: S411, construct a firefly population, set the firefly population size to N, the light intensity absorption coefficient to γ, the step size perturbation factor to α, the current number of iterations to t, and the maximum number of iterations to t max And the dimension of the search space for characteristic data of different network abnormal traffic types is P; Randomly generate N different network abnormal traffic type feature data in the different network abnormal traffic type feature data search space, each different network abnormal traffic type feature data corresponds to a firefly individual in the firefly population, and initialize the initial position set of the firefly population; S412, calculating the luminescence brightness of each firefly individual in the firefly population, arranging each firefly individual in the firefly population from large to small according to the luminescence brightness, and selecting the firefly individual with the highest luminescence brightness as the current optimal individual; S413, calculating the spatial distance between individual fireflies in the firefly population; S414, calculating the relative attraction between individual fireflies in the firefly population according to the spatial distance between individual fireflies in the firefly population; S415, each firefly individual in the firefly population is attracted by the firefly individual with higher luminous brightness to update its position in the search space of characteristic data of different network abnormal traffic types; The current best individual in the firefly population updates its position by randomly walking in the search space of characteristic data of different network abnormal traffic types; S416, calculating the luminous brightness of each firefly individual in the firefly population after the position is updated in the search space of the characteristic data of different network abnormal traffic types, if the luminous brightness of the firefly individual after the position is updated is greater than the luminous brightness of the original position, then the new position is used to replace the original position; otherwise, the original position is retained; S417, if the luminous brightness of the firefly individual in the search space of the characteristic data of different network abnormal traffic types is greater than the luminous brightness of the current optimal individual, then the firefly individual is used as the new current optimal individual; otherwise, directly enter S418; S418: Determine whether the current number of iterations t is less than the maximum number of iterations t max , if the current number of iterations t is less than the maximum number of iterations t max , then the current iteration number t is increased by 1, and the process returns to S413; otherwise, the current optimal individual is taken as the global optimal solution; S419, set a fitness function threshold. If the fitness function value of the global optimal solution is less than or equal to the fitness function threshold, it means that the real-time network environment is in a safe state, and output the real-time network traffic analysis data Q fenxi If the fitness function value of the global optimal solution is greater than the fitness function threshold, it means that the real-time network environment is in a dangerous state, and the real-time network traffic analysis data Q is output. fenxi The abnormal network traffic type feature data corresponding to the global optimal solution is anomaly, and the data is marked to generate real-time network abnormal traffic type feature data C leixing; S5. Establishing spatial location data of network abnormal traffic type blocking nodes; S6. Performing a blocking node spatial position search process according to the network abnormal traffic type blocking node spatial position data and the real-time network abnormal traffic type characteristic data to obtain the real-time network abnormal traffic blocking node spatial position data; S7. Construct real-time network abnormal traffic identification data based on the real-time network traffic analysis data, the real-time network abnormal traffic type feature data and the real-time network abnormal traffic blocking node spatial position data, and perform real-time network abnormal traffic blocking operations.

2. According to claim 1, a method for identifying and blocking abnormal network transmission based on data mining is characterized in that: The S1 comprises the following steps: S11, using the network traffic data collection unit to collect network traffic data of each node in real time, generating a real-time network traffic data set A={a1, a2, ..., a i ,…,a k }, where a i It represents the network traffic data of the ith node collected in real time by the network traffic data collection unit, k represents the total number of nodes through which the network traffic data passes, the network traffic data includes but is not limited to source IP address, destination IP address, data packet information, protocol information, traffic transmission rate and traffic distribution, the nodes through which the abnormal network traffic passes include but are not limited to core routers, switches, firewalls and important servers.

3. According to the method for identifying and blocking abnormal network transmission based on data mining according to claim 1, it is characterized in that: The S2 comprises the following steps: S21, performing network traffic data noise reduction processing on the real-time network traffic data in the real-time network traffic data set by using a bilateral filtering algorithm to generate a real-time network traffic feature data set ,in, represents the real-time network traffic characteristic data obtained after the ith real-time network traffic data in the real-time network traffic data set is subjected to network traffic data noise reduction processing; The performing network traffic data noise reduction processing on the real-time network traffic data in the real-time network traffic data set by using the bilateral filtering algorithm comprises the following steps: S211, selecting real-time network traffic data in the real-time network traffic data set as target sample data; S212, performing network traffic data noise reduction processing on the target sample data using a bilateral filtering noise reduction formula; S213, repeating the operations from S211 to S212 until all the real-time network traffic data in the real-time network traffic data set are traversed to generate a real-time network traffic feature data set.

4. According to the method for identifying and blocking abnormal network transmission based on data mining according to claim 1, it is characterized in that: The S3 comprises the following steps: S31. Establish a feature dataset of different network abnormal traffic types B={b1,b2,…,b i ,…,b l }, where b i It represents the network traffic characteristic data of each node passed when the i-th network abnormal traffic type appears, l represents the total number of characteristic data of different network abnormal traffic types, and the network abnormal traffic types include but are not limited to network traffic distribution abnormality, network traffic transmission rate abnormality, network traffic address abnormality, network attack abnormality and protocol information abnormality.

5. According to the method of claim 1, the method is characterized in that: The S5 comprises the following steps: S51, using a network traffic blocking node data storage unit to preset corresponding blocking node spatial position data for different network abnormal traffic type feature data in the different network abnormal traffic type feature data sets, generating a network abnormal traffic type blocking node spatial position data set D = {d1, d2, ..., d i ,…,d l }, where d i Represents the spatial location data of the blocking node corresponding to the i-th network abnormal traffic type.

6. According to the method of claim 1, the method is characterized in that: The S6 comprises the following steps: S61, using a breadth-first search algorithm to search the real-time network abnormal traffic type feature data C leixing The network abnormal traffic type blocking node spatial position data in the network abnormal traffic type blocking node spatial position data set are searched for the blocking node spatial position, all the network abnormal traffic type blocking node spatial position data in the network abnormal traffic type blocking node spatial position data set are traversed, and the real-time network abnormal traffic type feature data C is searched for. leixing The corresponding network abnormal traffic type matches the network abnormal traffic type and blocks the node spatial location data and performs data identification to generate real-time network abnormal traffic blocking node spatial location data E shishi .

7. According to the method of claim 1, the method is characterized in that: The S7 comprises the following steps: S71, the real-time network traffic analysis data Q fenxi , the real-time network abnormal traffic type characteristic data C leixing and the real-time network abnormal traffic blocking node spatial location data E shishi Combine data to build real-time network abnormal traffic identification data F=(Q fenxi ,C leixing ,E shishi ); S72, transmitting the real-time network abnormal traffic identification data F=(Q fenxi ,C leixing ,E shishi ) is pushed to the network abnormal traffic identification and blocking platform, and performs real-time network abnormal traffic blocking operations.

8. A system for implementing the network abnormal transmission identification and blocking method based on data mining as described in any one of claims 1 to 7; the system comprises a real-time network traffic data acquisition module, a real-time network traffic data preprocessing module, a module for establishing characteristic data of different network abnormal traffic types, a real-time network abnormal traffic type analysis module, a network abnormal traffic type blocking node spatial position data preset module, a real-time network abnormal traffic blocking node spatial position search module and a real-time network abnormal traffic identification data construction module; The real-time network traffic data collection module collects the network traffic data of each node passing through the network traffic data collection unit in real time and generates real-time network traffic data; The real-time network traffic data preprocessing module performs network traffic data noise reduction processing on the real-time network traffic data in the real-time network traffic data set by using a bilateral filtering algorithm to generate real-time network traffic feature data; The module for establishing characteristic data of different network abnormal traffic types establishes characteristic data of different network abnormal traffic types; The real-time network abnormal traffic type analysis module performs real-time network abnormal traffic type analysis processing on the real-time network traffic feature data and the different network abnormal traffic type feature data through the firefly optimization algorithm to generate real-time network traffic analysis data. If the real-time network traffic analysis data is normal, the network traffic identification operation is terminated. If the real-time network traffic analysis data is abnormal, then real-time network abnormal traffic type feature data is generated; The network abnormal traffic type blocking node spatial position data preset module presets corresponding blocking node spatial position data for the characteristic data of different network abnormal traffic types through the network traffic blocking node data storage unit, and generates network abnormal traffic type blocking node spatial position data; The real-time network abnormal traffic blocking node spatial position search module performs blocking node spatial position search processing on the network abnormal traffic type blocking node spatial position data and the real-time network abnormal traffic type characteristic data through a breadth-first search algorithm to obtain the real-time network abnormal traffic blocking node spatial position data; The real-time network abnormal traffic identification data construction module combines the real-time network traffic analysis data, the real-time network abnormal traffic type feature data and the real-time network abnormal traffic blocking node spatial position data to construct real-time network abnormal traffic identification data, and pushes it to the network abnormal traffic identification and blocking platform through the wireless communication network, while performing real-time network abnormal traffic blocking operations.

Citation Information

Patent Citations

  • Network intrusion detection and active defense linkage control device

    CN106330964A

  • Opportunity network evolution algorithm and device for promoting node cooperation

    CN105682174A

  • Network traffic prediction method based on discrete wavelet transform and FA-ELM

    CN113411216A