An automatic recognition and warning system for large-flow network information dissemination
By designing an automatic identification and warning system for information dissemination of large-traffic networks, the limitations of network traffic abnormality detection and analysis in the existing technology are solved, and a comprehensive investigation from the base station network to the software platform is realized, and the accuracy and security protection capabilities of abnormality detection are improved.
Patent Information
- Application Number
- CN202411891889.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2044-12-20
AI Technical Summary
The existing technology has limitations in network traffic abnormality detection and analysis, and it is difficult to conduct a comprehensive investigation from the macro base station network coverage partition to the micro software platform application level, resulting in the abnormality detection and analysis results that are not reliable and accurate.
A large-traffic network information dissemination automatic identification and warning system is designed, including network traffic abnormality identification module, suspicious source IP screening module, user behavior risk assessment module, warning work development module and cloud database. The system collects and analyzes network traffic data, identifies abnormal traffic, filters suspicious source IP, evaluates user behavior risks, and carries out related warning work.
It realizes a comprehensive investigation from macro base station network coverage partitioning to micro software platform application level, which can more comprehensively evaluate the health status of network traffic and improve the accuracy of abnormal detection and security protection capabilities.
Smart Images

Figure CN119584130B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network information dissemination, and specifically relates to an automatic identification and warning system for large-traffic network information dissemination. Background Art
[0002] In the digital age, the network has become the main channel for information dissemination. With the popularization of the Internet and the continuous progress of technology, network traffic has shown an explosive growth, and the speed and scope of information dissemination have expanded unprecedentedly. However, the dissemination of large-traffic network information also brings many challenges. In particular, the emergence of abnormal network traffic behaviors may indicate potential network security threats or the spread of bad information. Therefore, developing a system that can automatically identify and warn of abnormal network traffic behaviors is of great significance for maintaining the health and security of the network environment.
[0003] In the prior art, there are also some related solutions involving the detection and analysis of abnormal network traffic. For example, a network traffic supervision abnormal identification and early warning method and system with the Chinese patent publication number CN118631589B generates a first derivative network data stream containing richer information by performing feature derivation processing on the first basic network data stream, and merges it with the first basic network data stream to form a mixed network data stream. Through the detection and analysis of multiple abnormal identification tags, abnormal warning data for the first derivative network data stream is generated, providing strong support for timely discovering and coping with network security threats, and significantly improving the accuracy of network abnormal identification and the timeliness of early warning.
[0004] Another Chinese patent with the publication number CN106453392A, a method for identifying abnormal traffic flows in the entire network based on traffic feature distribution, performs coarse-grained abnormal identification on the network data flows in the entire network, extracts the node pairs with abnormal traffic from the entire network, and determines the feature categories of the abnormal traffic. Then, based on the extracted feature categories and abnormal node pairs, fine-grained abnormal identification is performed to determine the abnormal traffic feature values. Finally, based on the determined abnormal traffic feature values, an abnormal flow set is collected from the abnormal node pairs. Using a hierarchical method to identify abnormal traffic flows in the network data flows of the entire network not only improves the accuracy rate but also does not bring a huge amount of measurement and calculation work, accurately locates the abnormal node pairs in the entire network, and obtains traffic feature values such as the IP address and port number of the abnormal traffic in the abnormal node pairs.
[0005] Although the above solutions propose some methods for detecting and analyzing abnormal network traffic, the existing technologies still have the following limitations: 1. The existing technologies are limited to the source and analysis of network traffic data at the base station or platform level. Starting only from the perspective of the base station, only the overall in and out situation of network traffic in a specific area and some basic transmission characteristics can be understood. It is difficult to deeply understand the specific application behaviors and potential risks behind the traffic. Starting only from the software platform, it is only limited to the traffic generated by user operations within the platform, and the transmission characteristics of the traffic at the network infrastructure level and the possible external impacts cannot be known, resulting in an inability to provide a comprehensive and multi-level understanding of network traffic, and thus the abnormal detection and analysis results are not reliable.
[0006] 2. The existing technologies for detecting and analyzing abnormal network traffic do not effectively consider the content of the network traffic data load and the related user operation behaviors. They are limited to analyzing network packet header information such as source IP address, port, and destination IP address, and cannot go deep into the load content to identify potential malicious activities or abnormal behaviors, making the abnormal detection and analysis results of network traffic inaccurate. Summary of the Invention
[0007] To overcome the deficiencies in the background technology, an embodiment of the present invention provides an automatic recognition and warning system for large-traffic network information dissemination, which can effectively solve the problems involved in the above background technology.
[0008] The object of the present invention can be achieved through the following technical solutions: An automatic recognition and warning system for large-traffic network information dissemination includes: a network traffic anomaly recognition module, a suspicious source IP screening module, a user behavior risk assessment module, a warning work execution module, and a cloud database.
[0009] The network traffic anomaly recognition module is connected to the suspicious source IP screening module, the suspicious source IP screening module is connected to the user behavior risk assessment module, the user behavior risk assessment module is connected to the warning work execution module, and the cloud database is respectively connected to the network traffic anomaly recognition module and the suspicious source IP screening module.
[0010] The network traffic anomaly recognition module is used to collect the current network traffic detection data of a certain communication coverage area of a specified base station, and identify whether there is an abnormal situation in the current network traffic usage of the specified base station in this communication coverage area. If an abnormality is identified, the communication coverage area of the specified base station is recorded as a review area.
[0011] The suspicious source IP screening module is used to trace the network traffic paths of each source IP within the current preset time period in the review area, and screen each suspicious source IP corresponding to the current abnormal network traffic usage in the review area, which is recorded as each review IP.
[0012] A user behavior risk assessment module, which is used to extract the user operation behavior data of the authorized software platform corresponding to the target IP address currently accessed by each review IP, and retrieve the degree of violation risk of the user operation behavior of each review IP for the software platform it currently accesses.
[0013] A warning work execution module, which is used to judge the violation risk level of the user operation behavior of each review IP for the software platform it currently accesses, and accordingly carry out relevant warning work.
[0014] A cloud database, which is used to store the historical network traffic detection logs of the communication coverage area of the specified base station, and store the blacklist of target IP addresses and the list of high-risk ports.
[0015] Compared with the prior art, the embodiments of the present invention at least have the following advantages or beneficial effects: (1) By comprehensively considering from the macroscopic base station network coverage area to the microscopic software platform application level, the present invention can not only grasp the distribution and change trend of the overall network traffic, but also accurately locate the abnormal traffic behavior on the specific software platform, so as to more comprehensively evaluate the health status of the network traffic.
[0016] (2) By comprehensively examining the abnormal degree of network traffic increase, the abnormal degree of network traffic protocol, and the abnormal degree of network traffic content in a communication coverage area of a specified base station, the present invention can identify whether there is an abnormal situation in the current network traffic usage of the communication coverage area of the specified base station. It not only pays attention to the quantity change of network traffic, but also deeply analyzes the protocol and content of the traffic, so as to provide a more comprehensive perspective for abnormal detection.
[0017] (3) By tracing the network traffic paths of each source IP in the current preset time period of the review area, and deeply analyzing the originating geographical location, passing ports, accessed target IP address, and start and end timestamps of the traffic session window, the present invention can effectively screen each suspicious source IP corresponding to the current abnormal network traffic usage in the review area, greatly improving the efficiency of network traffic review and the security protection ability.
[0018] (4) By examining the corresponding normative indicators of operation text type, operation image type, and operation permission type for each operation of each review IP for the authorized software platform corresponding to the target IP address it currently accesses, analyzing the degree of violation risk of the user operation behavior of each review IP for the software platform it currently accesses and judging the corresponding level, and accordingly carrying out warning work, the present invention can achieve comprehensive monitoring and effective management of user operation behavior, thereby improving the efficiency of security management and enhancing the compliance awareness of users. Description of the Drawings
[0019] The present invention will be further described with reference to the accompanying drawings. However, the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on the following drawings without creative efforts.
[0020] Figure 1 It is a schematic diagram of module connection of the present invention.
[0021] Figure 2 It is a bar chart of the usage proportion of network protocol types for reference indication of the present invention.
[0022] Figure 3 It is a reference schematic diagram of the network traffic path of the source IP in the current preset period of the review partition of the present invention. Detailed implementation manners
[0023] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0024] Refer to Figure 1 As shown, the present invention provides a large - flow network information dissemination automatic recognition and warning system, including: a network traffic anomaly recognition module, a suspicious source IP screening module, a user behavior risk assessment module, a warning work execution module, and a cloud database.
[0025] The network traffic anomaly recognition module is connected to the suspicious source IP screening module, the suspicious source IP screening module is connected to the user behavior risk assessment module, the user behavior risk assessment module is connected to the warning work execution module, and the cloud database is respectively connected to the network traffic anomaly recognition module and the suspicious source IP screening module.
[0026] The network traffic anomaly recognition module is used to collect the current network traffic detection data of a specified base station in a certain communication coverage area, identify whether there is an abnormal situation in the current network traffic usage of the specified base station in this communication coverage area. If an abnormality is identified, the communication coverage area of the specified base station is recorded as a review partition.
[0027] Specifically, the network traffic detection data includes the network traffic usage change curve in a preset period, the bar chart of the usage proportion of network protocol types, and the network traffic data load content.
[0028] The user operation behavior data includes the operation text content, operation image content, operation result logic indication, and operation object of each operation.
[0029] Specifically, the specific analysis process of the network traffic anomaly recognition module includes: extracting the network traffic usage change curves of the same period as the current preset period in each historical day with the same daily schedule nature in the current quarter from the historical network traffic detection logs of the specified base station in the communication coverage area stored in the cloud database, recording them as each sampled network traffic usage change curve, and comparing them with the network traffic usage change curve of the preset period in the current network traffic detection data of the specified base station in the communication coverage area to evaluate the abnormal degree of the current network traffic increase in the communication coverage area 。
[0030] It should be noted that the specific evaluation process above is as follows: By importing each sampled network traffic usage change curve and the network traffic usage change curve of the preset period of the specified base station in the communication coverage area into Matlab software to obtain their respective corresponding best fitting functions, which are respectively recorded as 、 where is the number of each sampled network traffic usage change curve, , import the network traffic usage change curve of the preset period of the specified base station in the communication coverage area into the second layer of the coordinate system of Matlab software, import each sampled network traffic usage change curve into the first layer of the coordinate system of Matlab software in turn, compare them with the network traffic usage change curve of the preset period of the specified base station in the communication coverage area in the second layer, retrieve each curve segment where the network traffic usage change curve of the preset period of the specified base station in the communication coverage area is relatively higher than each sampled network traffic usage change curve, record it as each over-amplitude curve segment in the current relative to each sampled network traffic usage change curve, extract the start and end time points of a certain over-amplitude curve segment in the current relative to a certain sampled network traffic usage change curve, and record them as , analyze the network traffic usage increase degree of the current relative to this over-amplitude curve segment in this sampled network traffic usage change curve by the formula , is the best fitting function of this sampled network traffic usage change curve, and thus obtain the network traffic usage increase degree of each over-amplitude curve segment in the current relative to each sampled network traffic usage change curve , is the number of each over-amplitude curve segment, , analyze the relative increase degree of the network traffic usage of the preset period of the specified base station in the communication coverage area by the formula where is the number of sampled network traffic usage change curves, and for the best fitting function Perform a first-order derivative and substitute it into each unit time point within the current preset time period. Retrieve the maximum value among them as the internal ratio increase degree of the network traffic usage within the current preset time period for the specified base station's communication coverage area. , and use the formula to calculate the abnormal degree of the current network traffic increase in this communication coverage area, where are the preset permission thresholds corresponding to the relative increase degree of network traffic usage and the internal ratio increase degree of network traffic usage respectively.
[0031] Refer to Figure 2 as shown, extract the column chart of the usage ratio of network protocol types for the same time period as the current preset time period in the historical network traffic detection logs of this communication coverage area of the specified base station for each day in the current quarter, and count the corresponding reference usage ratios of various network protocols for the current preset time period in this communication coverage area , is the number of each network protocol, , compare it with the column chart of the usage ratio of network protocol types in the current network traffic detection data of this communication coverage area for the preset time period, introduce the change trend factors of various network protocols, and evaluate the abnormal degree of the current network traffic protocol in this communication coverage area .
[0032] It should be noted that the specific evaluation process above is as follows: Subtract the usage ratio of each network protocol on the column chart of the usage ratio of network protocol types in the current network traffic detection data of this communication coverage area for the preset time period from its corresponding reference usage ratio, and record the difference result as . Sample the usage ratio of each network protocol on the column chart of the usage ratio of network protocol types for the same time period as the current preset time period in the historical network traffic detection logs of each day in the current quarter, construct the change curve of the usage ratio of various network protocols for the historical preset time period in the current quarter and generate its corresponding best-fit function, substitute the current day's time into the best-fit function after the first-order derivative, and thus obtain the change trend factors of various network protocols , and analyze the abnormal degree of the current network traffic protocol in this communication coverage area from the formula , where is a preset constant to prevent the denominator from being 0.
[0033] It also should be noted that the corresponding reference usage ratios of various network protocols for the current preset time period in this communication coverage area in the current quarter are obtained by calculating the average value of the usage ratio of the corresponding type of network protocol within the column chart of the usage ratio of network protocol types for the same time period as the current preset time period in the historical network traffic detection logs of this communication coverage area of the specified base station for each day in the current quarter.
[0034] Sieve the network traffic data load content of the current communication coverage area during a preset period into encrypted content and unencrypted content, and then evaluate the abnormality degree of the current network traffic content in the communication coverage area .
[0035] Specifically, the specific analysis process of the network traffic anomaly recognition module further includes: From the formula Analyze the current network traffic comprehensive usage anomaly index of the communication coverage area, where Are the corresponding permission thresholds for the preset network traffic increase anomaly degree, network traffic protocol anomaly degree, and network traffic content anomaly degree respectively. If the current network traffic comprehensive usage anomaly index of the communication coverage area is greater than or equal to the preset value, it is recognized that there is an abnormal situation in the current network traffic usage of the specified base station in this communication coverage area, otherwise it is recognized that there is no such situation.
[0036] Specifically, the specific evaluation process of the Includes: Extract each keyword in the unencrypted content of the network traffic data load of the current preset period in the communication coverage area, and compare them with the keyword sets related to malware in the preset specification and the keyword sets related to sensitive information in the preset specification respectively. Retrieve the proportion of the number of keywords related to malware and the proportion of the number of keywords related to sensitive information in the unencrypted content of the network traffic data load of the current preset period in the communication coverage area, and use the cumulative value of the two as the abnormality degree of the current network traffic unencrypted content in the communication coverage area .
[0037] Verify the credibility of the encryption certificate used in the encrypted content of the network traffic data load of the current preset period in the communication coverage area, and use its reciprocal as the abnormality degree of the current network traffic encrypted content in the communication coverage area .
[0038] It should be noted that the specific verification process for the credibility of the encryption certificate used for the network traffic data load encryption content in the current preset period of the above communication coverage area is as follows: Trace back the certificate chain of the encryption certificate used for the network traffic data load encryption content in the current preset period of the communication coverage area to detect whether there is an interruption in the certificate chain, and check the expiration date of the encryption certificate used for the network traffic data load encryption content in the current preset period of the communication coverage area to detect whether it is within the expiration date on the current day. If it is detected that there is an interruption in the certificate chain or it is outside the expiration date on the current day, output that the credibility of the encryption certificate used for the network traffic data load encryption content in the current preset period of the communication coverage area is 0. If it is detected that there is no interruption in the certificate chain and it is within the expiration date on the current day, output that the credibility of the encryption certificate used for the network traffic data load encryption content in the current preset period of the communication coverage area is 1. It should be particularly noted that when calculating the reciprocal of the credibility of the encryption certificate used for the network traffic data load encryption content in the current preset period of the above communication coverage area, a preset constant needs to be added to the denominator to prevent the denominator from being 0.
[0039] Sum the products of and respectively with their corresponding preset weights to obtain the degree of abnormality of the current network traffic content in the communication coverage area.
[0040] In the embodiment of the present invention, by comprehensively examining the degree of abnormality of the network traffic increase, the degree of abnormality of the network traffic protocol, and the degree of abnormality of the network traffic content in a certain communication coverage area of a specified base station, it is possible to identify whether there is an abnormal situation in the current network traffic usage in the communication coverage area of the specified base station. It not only pays attention to the quantity change of the network traffic, but also deeply analyzes the protocol and content of the traffic, thereby providing a more comprehensive perspective for anomaly detection.
[0041] Referring to Figure 3 as shown, the suspicious source IP screening module is used to trace and review the network traffic paths of each source IP in the current preset period of the review partition, and screen each suspicious source IP corresponding to the abnormal network traffic usage in the current review partition, denoted as each review IP.
[0042] Specifically, the specific analysis process of the suspicious source IP screening module includes: obtaining the originating geographical location, traversed ports, accessed target IP address, and start and end timestamps of each traffic session window of each source IP in the current preset period of the review partition.
[0043] According to the blacklist of target IP addresses and the list of high-risk ports stored in the cloud database, compare and review whether the target IP addresses accessed by each source IP in each traffic session window within the current preset period of the review partition belong to the blacklist, and whether the ports passed through belong to the list of high-risk ports. If the target IP address accessed by a certain source IP in a certain traffic session window belongs to the blacklist or the port passed through belongs to the list of high-risk ports, then directly list the source IP as a risk source IP for warning work.
[0044] It should be noted that the warning work for the above risk source IP corresponds to the highest level of violation risk.
[0045] If the target IP addresses accessed by each traffic session window of a certain source IP do not belong to the blacklist and the ports passed through do not belong to the list of high-risk ports, then further obtain the replacement frequency of the port types passed through by the source IP and the total data transmission volume of the target IP addresses accessed by each traffic session window. Respectively evaluate the compliance coefficient of the ports passed through by the traffic session window of the source IP and the compliance coefficient of the accessed data. If the compliance coefficient of the ports passed through is less than the preset compliance coefficient threshold for the ports passed through or the compliance coefficient of the accessed data is less than the preset compliance coefficient threshold for the accessed data, then regard the source IP as a suspicious source IP corresponding to the current abnormal network traffic.
[0046] It should be noted that the evaluation process of the compliance coefficient of the ports passed through by the traffic session window of the source IP is as follows: Take the difference between the replacement frequency of the port types passed through by the source IP and the preset reasonable replacement frequency of the port types passed through, and record the calculated difference as , and analyze the compliance coefficient of the ports passed through by the traffic session window of the source IP according to the formula .
[0047] The evaluation process of the compliance coefficient of the accessed data of the traffic session window of the source IP is as follows: Extract the total data transmission volume of the target IP addresses accessed by each traffic session window of the source IP, retrieve the average total data transmission volume of the traffic session windows of the source IP accessing each target IP address in the historical network traffic detection logs of the specified base station in the communication coverage partition, and thus retrieve the historical average total data transmission volume of the target IP addresses accessed by each traffic session window of the source IP. Take the difference between the total data transmission volume of the target IP addresses accessed by each traffic session window of the source IP and the historical average total data transmission volume, and calculate the compliance coefficient of the accessed data of the traffic session window of the source IP in the same way as the calculation method of the compliance coefficient of the ports passed through by the traffic session window of the source IP.
[0048] Specifically, the specific analysis process of the suspicious source IP screening module further includes: calculating the duration of each traffic session window of each source IP within the current preset time period of the review partition, and the geographical location spacing and interval duration between the current traffic session window and the previous traffic session window of each source IP, respectively evaluating the position change compliance coefficient and the interval duration compliance coefficient of each source IP traffic session window within the current preset time period of the review partition. If the position change compliance coefficient of a certain source IP traffic session window is less than the preset position change compliance coefficient standard threshold or the interval duration compliance coefficient is less than the preset interval duration compliance coefficient standard threshold, then use the source IP as the current abnormal network traffic and use the corresponding suspicious source IP.
[0049] It should be noted that the specific evaluation process of the position change compliance coefficient and the interval duration compliance coefficient of each source IP traffic session window within the current preset time period of the review partition is as follows: extract the geographical location spacing between the current traffic session window of each source IP and the previous traffic session window within the current preset time period of the review partition. If the geographical location spacing between a certain traffic session window and the previous traffic session window is greater than the preset reasonable spacing threshold, it means that there is a phenomenon of high-amplitude change in the source IP position of this traffic session window, and retrieve the number of times of high-amplitude change phenomena of each source IP within the current preset time period of the review partition and the maximum number of consecutive high-amplitude change phenomena , where is the number of each source IP within the current preset time period of the review partition, , from the formula analyze the position change compliance coefficient of each source IP traffic session window within the current preset time period of the review partition, where is the number of times of the th source IP traffic session window within the current preset time period of the review partition.
[0050] Extract the duration of each traffic session window of each source IP within the current preset time period of the review partition and the interval duration between the current traffic session window and the previous traffic session window , is the number of each traffic session window, , from the formula analyze the interval duration compliance coefficient of each source IP traffic session window within the current preset time period of the review partition, where is the preset reasonable interval duration threshold between adjacent traffic session windows, is the preset reasonable reference duration of the traffic session window, and its data is obtained from the reasonable duration interval of the traffic session window provided in the network practice guide of the specified base station, and the mean value is calculated for the upper and lower limit values of the interval. is the preset reasonable deviation duration of the traffic session window, and its data source is the calculated difference between the preset reasonable reference duration of the traffic session window and the lower limit value of the reasonable duration interval of the traffic session window. is the number of traffic session windows.
[0051] It should be noted that when reviewing the compliance coefficient of the interval duration of each source IP traffic session window in the current preset period of the above analysis review partition, the basis for the proportional relationship between the interval duration of each source IP traffic session window and its previous traffic session window in the current preset period of the review partition is as follows: If the interval duration between adjacent traffic session windows is too short, or even a certain session window is opened before its previous window ends, it indicates frequent operations of the source IP, which is an abnormal phenomenon. And the opening of the session window is usually determined by the user's operation intention. If the interval duration between adjacent traffic session windows is generally long, the possibility of frequent operations can be excluded, so it is in a proportional relationship.
[0052] In summary, screen each suspicious source IP corresponding to the current abnormal network traffic usage in the review partition.
[0053] In the embodiment of the present invention, by tracing the network traffic path of each source IP in the current preset period of the review partition and deeply analyzing the originating geographical location, passing ports, accessed target IP address, and start and end timestamps of the traffic session window, effective screening of each suspicious source IP corresponding to the current abnormal network traffic usage in the review partition is realized, greatly improving the efficiency of network traffic review and the security protection ability.
[0054] The user behavior risk assessment module is used to extract the user operation behavior data of the target IP address corresponding to the authorized software platform currently accessed by each review IP, and retrieve the degree of violation risk of the user operation behavior of each review IP for the software platform it currently accesses.
[0055] Specifically, the specific analysis process of the user behavior risk assessment module includes: extracting the operation text content and operation image content of each operation in the user operation behavior data of the target IP address corresponding to the authorized software platform currently accessed by each review IP, performing string conversion on the operation text content, and combining the defined regular expression library provided by the authorized software platform corresponding to the target IP address currently accessed by each review IP to verify and output the operation text type normalization indexes of each operation of each review IP for the authorized software platform corresponding to the target IP address it currently accesses. , where is the number of each review IP, , is the number of each operation, .
[0056] It should be noted that the above The verification output can be specifically obtained by converting the string into the operation text content and importing the defined regular expression library into the text processing software, and using each preset rule in the defined regular library to verify the operation text content one by one. If the operation text content matches a certain preset rule, the matching status index of the preset rule is output as 1. If the operation text content does not match a certain preset rule, the matching status index of the preset rule is output as 0. Extract the preset weights of each preset rule in the defined regular library, integrate the matching status indexes of the operation text content relative to each preset rule in the defined regular library and multiply them by their corresponding preset weights, and accumulate them to obtain the operation text type norm index, thereby obtaining the operation text type norm indexes of each review IP for each operation of the authorized software platform corresponding to the target IP address it currently accesses.
[0057] Exemplarily, the above text processing software can be specifically UltraEdit, Notepad++, SPSS, SAS.
[0058] It should be specifically noted that the defined regular expression library provided by the above authorized software platform refers to a series of regular expression rules that are pre-formulated by the platform according to its own operation specifications, business logics, etc. and are used to match and verify legal and standard operation text formats.
[0059] For the operation image content, collect image elements, and combine the defined standard image element library provided by the authorized software platform corresponding to the target IP address currently accessed by each review IP to verify and output the operation image type norm indexes of each review IP for each operation of the authorized software platform corresponding to the target IP address it currently accesses. 。
[0060] It should be noted that the above The verification output process is as follows: Compare each image element in the operation image content of a certain operation of the authorized software platform corresponding to the target IP address currently accessed by a certain review IP with each image element in the defined standard image element library provided by the authorized software platform corresponding to the target IP address currently accessed by this review IP, count the number of image elements in the defined standard image element library of the authorized software platform corresponding to the target IP address currently accessed by this review IP to which the operation image content of this operation of this review IP belongs, perform a ratio analysis with the total number of image elements collected in the operation image content of this operation, and obtain the operation image type norm index of this review IP for this operation of the authorized software platform corresponding to the target IP address it currently accesses, thereby verifying the operation image type norm indexes of each review IP for each operation of the authorized software platform corresponding to the target IP address it currently accesses.
[0061] Extract the logical indication of the operation result and the operation object of each operation in the user operation behavior data of the authorized software platform corresponding to the target IP address currently accessed by each review IP, verify and output the normative indicators of the operation permission category for each operation of each review IP on the authorized software platform corresponding to its currently accessed target IP address 。
[0062] It should be noted that the above The verification and output process is as follows: The logical indication value of the operation result is 1 or 0, where 1 indicates successful operation and 0 indicates failed operation. Obtain the user identity of each review IP for the authorized software platform corresponding to the target IP address it currently accesses and the corresponding user permission scope, and detect whether the operation object of each operation in the user operation behavior data of the authorized software platform corresponding to the target IP address currently accessed by each review IP is within its corresponding user permission scope. If the operation object of a certain operation is within its corresponding user permission scope, then assign the normative indicator of the operation permission category for this operation as ; if the operation object of a certain operation is outside its corresponding user permission scope and the logical indication of the operation result is 0, then assign the normative indicator of the operation permission category for this operation as ; if the operation object of a certain operation is outside its corresponding user permission scope and the logical indication of the operation result is 1, then assign the normative indicator of the operation permission category for this operation as where Thus, output the normative indicators of the operation permission category for each operation of each review IP on the authorized software platform corresponding to its currently accessed target IP address.
[0063] Specifically, the specific analysis process of the user behavior risk assessment module further includes: From the formula Analyze the degree of violation risk of the user operation behavior of each review IP for the software platform it currently accesses, where are the preset weights of the normative indicators corresponding to the operation text type, operation image type, and operation permission type respectively, is the number of operations.
[0064] Exemplarily, the above can be specifically taken as 。
[0065] The warning work development module is used to judge the violation risk level of the user operation behavior of each review IP for the software platform it currently accesses, and accordingly carry out relevant warning work.
[0066] Specifically, the specific analysis process of the warning work module includes: performing a ratio analysis on the violation risk degree of each reviewed IP user's operation behavior for the software platform currently accessed by it and the preset benchmark violation risk degree, and taking the ceiling of the ratio analysis result as the violation risk level of each reviewed IP user's operation behavior for the software platform currently accessed by it, and designating the base station to give warnings and restrict the activities of each reviewed IP according to the level.
[0067] In the embodiment of the present invention, by examining the corresponding normative indicators of the operation text type, operation image type, and operation permission type for each operation of each reviewed IP for the authorized software platform corresponding to the target IP address currently accessed by it, analyzing the violation risk degree of each reviewed IP user's operation behavior for the software platform currently accessed by it and judging the corresponding level, and carrying out warning work accordingly, the comprehensive monitoring and effective management of the user's operation behavior are realized, thereby improving the efficiency of security management and enhancing the compliance awareness of users.
[0068] The cloud database is used to store the historical network traffic detection logs of the communication coverage area of the designated base station, and store the blacklist of target IP addresses and the list of high-risk ports.
[0069] In the embodiment of the present invention, through a comprehensive consideration from the macro base station network coverage area to the micro software platform application level, not only grasping the distribution and change trend of the overall network traffic, but also accurately positioning the abnormal traffic behavior on the specific software platform, so as to more comprehensively evaluate the health status of the network traffic.
[0070] The above content is only an example and explanation of the structure of the present invention. Those skilled in the art of the present technology make various modifications or supplements to the described specific embodiments or use similar methods to replace them, as long as they do not deviate from the structure of the invention or exceed the scope defined by the present invention, they should all belong to the protection scope of the present invention.
Claims
1. A high-volume network information transmission automatic identification and warning system, characterized in that: The system includes: The network traffic anomaly identification module is used to collect the current network traffic detection data of a communication coverage zone of the specified base station, identify whether there is an abnormality in the current network traffic usage of the communication coverage zone of the specified base station, and if so, record the communication coverage zone of the specified base station as a review zone; The suspicious source IP screening module is used to trace the network traffic path of each source IP in the current preset time period of the review partition, and screen the suspicious source IPs corresponding to the current abnormal network traffic in the review partition, which are recorded as each review IP; The user behavior risk assessment module is used to extract the user operation behavior data of the authorized software platform corresponding to the target IP address currently accessed by each review IP, and retrieve the violation risk level of each review IP user operation behavior for the software platform currently accessed; The warning work implementation module is used to judge the violation risk level of each IP user's operation behavior for the software platform they are currently accessing, and carry out relevant warning work accordingly; The cloud database is used to store the historical network traffic detection logs of the communication coverage area of the specified base station, and store the target IP address blacklist and high-risk port list.
2. According to claim 1, a high-volume network information transmission automatic identification and warning system is characterized by: The network traffic detection data includes a network traffic usage change curve for a preset period, a network protocol type usage ratio bar chart, and network traffic data load content; The user operation behavior data includes the operation text content, operation image content, operation result logic indication and operation object of each operation.
3. According to claim 2, a high-volume network information transmission automatic identification and warning system is characterized by: The specific analysis process of the network traffic anomaly identification module includes: extracting the network traffic usage change curve of the same period as the current preset period in the historical days with the same schedule nature as the current season from the historical network traffic detection log of the communication coverage partition of the designated base station stored in the cloud database, and comparing it with the network traffic usage change curve of the preset period in the current network traffic detection data of the communication coverage partition of the designated base station, and evaluating the abnormal degree of the current network traffic increase of the communication coverage partition ; Extract the network protocol type usage ratio bar chart of the same period as the current preset period in the historical network traffic detection log of the communication coverage partition of the specified base station, and count the corresponding reference usage ratios of various network protocols in the current preset period of the season in the communication coverage partition, and compare them with the network protocol type usage ratio bar chart of the preset period in the current network traffic detection data of the communication coverage partition, introduce various network protocol change trend factors, and evaluate the current abnormality of the network traffic protocol in the communication coverage partition ; Screen the network traffic data load content of the preset period in the current network traffic detection data of the communication coverage partition as encrypted content and non-encrypted content, and then evaluate the abnormality of the current network traffic content of the communication coverage partition .
4. According to claim 3, a high-volume network information transmission automatic identification and warning system is characterized by: The specific analysis process of the network traffic anomaly identification module also includes: By formula Analyze the current network traffic comprehensive usage abnormal indicators of the communication coverage area, including The preset network traffic increase rate abnormality degree, network traffic protocol abnormality degree, and network traffic content abnormality degree correspond to the permitted thresholds. If the current network traffic comprehensive usage abnormality index of the communication coverage partition is greater than or equal to the preset value, it is identified that the current network traffic usage of the communication coverage partition of the designated base station is abnormal, otherwise it is identified that there is no abnormality.
5. According to claim 3, a high-volume network information transmission automatic identification and warning system is characterized by: Said The specific evaluation process includes: extracting each keyword in the non-encrypted content of the network traffic data load of the communication coverage partition during the current preset period, comparing it with the preset standard malware-related keyword set and the preset standard sensitive information-related keyword set, retrieving the proportion of malware-related keywords and the proportion of sensitive information-related keywords in the non-encrypted content of the network traffic data load of the communication coverage partition during the current preset period, and taking the cumulative value of the two as the abnormality level of the current non-encrypted content of the network traffic of the communication coverage partition ; Verify the credibility of the encryption certificate used for the encrypted content of the network traffic data load in the current preset period of the communication coverage partition, and use its reciprocal as the abnormality level of the current network traffic encryption content in the communication coverage partition ; Will , The products of the corresponding preset weights are respectively accumulated to obtain the abnormality level of the current network traffic content of the communication coverage partition.
6. According to claim 1, a high-volume network information transmission automatic identification and warning system is characterized by: The specific analysis process of the suspicious source IP screening module includes: obtaining the initiating geographical location, traversed ports, access target IP address and start and end timestamps of each flow session window of each source IP within the current preset time period of the review partition; According to the target IP address blacklist and high-risk port list stored in the cloud database, compare and review whether the target IP address corresponding to each traffic session window of each source IP in the current preset period belongs to the blacklist, and whether the port passed through belongs to the high-risk port list. If a traffic session window of a source IP corresponds to the blacklist to which the target IP address belongs or the high-risk port list to which the port passed through belongs, the source IP is directly listed as a risk source IP for warning; If the target IP addresses accessed in each traffic session window of a source IP do not belong to the blacklist and the ports passed through do not belong to the high-risk port list, then the frequency of changing the port type passed through of the source IP and the total data transmission volume of the target IP addresses accessed in each traffic session window are further obtained, and the compliance coefficient of the ports passed through and the compliance coefficient of the access data of the source IP traffic session window are evaluated respectively. If the compliance coefficient of the ports passed through is less than the preset compliance coefficient threshold of the ports passed through or the compliance coefficient of the access data is less than the preset compliance coefficient threshold of the access data, then the source IP is used as the suspicious source IP corresponding to the current abnormal network traffic.
7. The automatic identification and warning system for large-volume network information transmission according to claim 6 is characterized by: The specific analysis process of the suspicious source IP screening module also includes: calculating the duration of each flow session window of each source IP in the current preset time period of the review partition, and the distance and interval duration between the initiating geographical location of the window and the previous flow session window, respectively evaluating the position change compliance coefficient and the interval compliance coefficient of each source IP flow session window in the current preset time period of the review partition, if the position change compliance coefficient of a source IP flow session window is less than the preset position change compliance coefficient compliance threshold or the interval compliance coefficient is less than the preset interval compliance coefficient compliance threshold, then the source IP is used as the suspicious source IP corresponding to the current abnormal network traffic; In summary, the current abnormal network traffic in the screening and review partition uses the corresponding suspicious source IPs.
8. The automatic identification and warning system for large-volume network information transmission according to claim 2 is characterized by: The specific analysis process of the user behavior risk assessment module includes: extracting the operation text content and operation image content of each operation in the user operation behavior data of the authorized software platform corresponding to the target IP address currently visited by each review IP, performing string conversion on the operation text content, and combining the definition regular expression library provided by the authorized software platform corresponding to the target IP address currently visited by each review IP, verifying and outputting the operation text normative indicators of each review IP for each operation of the authorized software platform corresponding to the target IP address currently visited by it ,in is the number of each review IP, , is the number of each operation, ; Image elements are collected based on the content of the operation images. Based on the definition and specification image element library provided by the authorized software platform corresponding to the target IP address currently accessed by each review IP, the operation image specification indicators of each operation performed by each review IP on the authorized software platform corresponding to the target IP address currently accessed are verified and output. ; Extract the logical indications and operation objects of the operation results of each operation in the user operation behavior data of the authorized software platform corresponding to the target IP address currently accessed by each review IP, verify and output the normative indicators of the operation permissions of each review IP for each operation of the authorized software platform corresponding to its current target IP address. .
9. The automatic identification and warning system for large-volume network information transmission according to claim 8 is characterized by: The specific analysis process of the user behavior risk assessment module also includes: By formula Analyze the violation risk level of each IP user's operation behavior against the software platform they are currently accessing. Preset weights for normative indicators corresponding to the operation text category, operation image category, and operation authority category. is the number of operations.
10. The automatic identification and warning system for large-volume network information transmission according to claim 1 is characterized by: The specific analysis process of the warning work implementation module includes: performing a ratio analysis on the violation risk level of each reviewed IP user's operation behavior for the software platform they are currently accessing and the preset benchmark violation risk level, taking the integer of the ratio analysis result as the violation risk level of each reviewed IP user's operation behavior for the software platform they are currently accessing, and specifying the base station to issue warnings and restrict the activities of each reviewed IP according to the level.
Citation Information
Patent Citations
Whole-network abnormal flow identification method based on flow characteristic distribution
CN106453392A
A network traffic supervision anomaly identification and early warning method and system
CN118631589B
Abnormal network connection identification and detection method for data transmission
CN118659898A
Methods, Devices and Computer Program Products for Actionable Alerting of Malevolent Network Addresses Based on Generalized Traffic Anomaly Analysis of IP Address Aggregates
US20120117254A1