A network intrusion detection method, device, equipment and data security product
By acquiring network attack information and device status indicators to calculate network situation and combining them with danger values for early warning, the problem of the inability to provide timely early warning in existing technologies has been solved, and network intrusion warnings have been achieved.
Patent Information
- Application Number
- CN202411759208.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-03
- Publication Date
- 2026-02-24
- Estimated Expiration
- 2044-12-03
AI Technical Summary
Existing network intrusion detection technologies cannot provide timely warnings before network intrusions occur, nor can they identify potential intrusion risks in advance.
By acquiring network attack information, device usage status, and network performance indicators of the device under test over a historical period, the current network situation is calculated, and the intrusion risk is determined based on the danger value and network situation, and a threshold is set for early warning.
It enables timely early warning before network intrusions occur, improving the foresight and reliability of network security and reducing the risk of network attacks.
Smart Images

Figure CN119652587B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a network intrusion detection method, apparatus, device, and data security product. Background Technology
[0002] Intrusion detection technology is a result of the continuous development of network technology. Currently, network intrusion detection solutions monitor information on computer networks and determine whether a network attack has occurred based on the monitored information. This type of network intrusion detection solution can only determine that a network intrusion has occurred after a network attack has taken place, and it cannot provide timely warnings before a network intrusion occurs. Summary of the Invention
[0003] Based on this, the present invention provides a network intrusion detection method, apparatus, device, and data security product to address the shortcomings of existing technologies that cannot provide timely warnings before network intrusions occur.
[0004] To achieve the above objectives, embodiments of the present invention provide a network intrusion detection method, comprising:
[0005] Obtain network attack information, device usage status, and network performance indicators of the device under test within a historical time period;
[0006] Calculate the current network situation based on the device usage status and the network performance indicators;
[0007] The danger level of the device to be detected is determined based on the network attack information.
[0008] An intrusion warning is initiated when the danger value exceeds a set danger threshold or the current network risk value exceeds a set situation threshold; wherein, the current network risk value is positively correlated with the danger value and the current network situation, respectively.
[0009] To achieve the above objectives, embodiments of the present invention also provide a network intrusion detection device, comprising:
[0010] The information acquisition module is used to acquire network attack information, device usage status and network performance indicators of the device under test within a historical time period.
[0011] The network situation calculation module is used to calculate the current network situation based on the device usage status and the network performance indicators.
[0012] A danger value calculation module is used to determine the danger value of the device to be detected based on the network attack information.
[0013] The early warning module is used to initiate an intrusion warning when the danger value is greater than a set danger threshold or the current network risk value is greater than a set situation threshold; wherein the current network risk value is positively correlated with the danger value and the current network situation, respectively.
[0014] To achieve the above objectives, this invention also provides a data security product, which is a data center. The data center includes a data sharing service layer, and the network intrusion detection method described in any of the above embodiments is applied to the data sharing security function module of the data sharing service layer.
[0015] Alternatively, the data security product is a data platform, which is used to execute the network intrusion detection method as described in any of the above embodiments;
[0016] Alternatively, the data security product may be a capability sharing platform, which is used to execute the network intrusion detection method as described in any of the above embodiments.
[0017] To achieve the above objectives, embodiments of the present invention also provide a network intrusion detection device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the network intrusion detection method as described in any of the above embodiments.
[0018] To achieve the above objectives, embodiments of the present invention also provide a computer-readable storage medium, the computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the network intrusion detection method as described in any of the above embodiments.
[0019] To achieve the above objectives, embodiments of the present invention also provide a computer program product, including a computer program / instructions, which, when executed by a processor, implement the network intrusion detection method as described in any of the above embodiments.
[0020] Compared with existing technologies, the network intrusion detection method, apparatus, device, data security product, computer-readable storage medium, and computer program product disclosed in this invention first acquire network attack information, device usage status, and network performance indicators of the device to be detected over a historical period. Then, the current network situation is calculated based on the device usage status and network performance indicators, and the danger value of the device to be detected is determined based on the network attack information. Finally, an intrusion warning is initiated when the danger value exceeds a set danger threshold or the current network risk value exceeds a set situation threshold. The current network risk value is positively correlated with both the danger value and the current network situation. Therefore, this invention analyzes the current network situation based on device usage status and network performance indicators, and combines this with past network attack information to analyze the current network intrusion risk, enabling timely warnings when the intrusion risk is high, thus achieving the goal of timely warning before a network intrusion occurs. Attached Figure Description
[0021] To more clearly illustrate the technical solution of the present invention, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 This is a flowchart illustrating a network intrusion detection method according to an embodiment of the present invention;
[0023] Figure 2 This is a schematic diagram of the structure of a network intrusion detection device provided in an embodiment of the present invention;
[0024] Figure 3 This is a schematic diagram of the structure of a network intrusion detection device provided in an embodiment of the present invention. Detailed Implementation
[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0026] See Figure 1 , Figure 1 This is a flowchart illustrating a network intrusion detection method provided in an embodiment of the present invention. Specifically, the network intrusion detection method includes steps S11 to S14:
[0027] S11. Obtain network attack information, device usage status, and network performance indicators of the device under test within a historical time period.
[0028] Specifically, the network intrusion detection method can be executed in real time or in response to a network intrusion detection command. The network intrusion detection command can be triggered automatically periodically, such as once a month, executing the network intrusion detection method at midnight on the first day of each month; the command can also be triggered by the user, such as by providing a trigger control, which triggers the network intrusion command when the user clicks the trigger control. Each time the network intrusion detection method is executed, it performs detection based on network data from a recent period (i.e., a historical time period). For example, in response to a network intrusion detection command, it obtains network data from the past month, including network attack information, device usage status, and network performance indicators.
[0029] S12. Calculate the current network status based on the device usage status and the network performance indicators.
[0030] Specifically, the device usage status is used to characterize the resource utilization of the device under test, and the network performance index is a key parameter for measuring the efficiency of a computer network, which determines the network's transmission capacity and data processing efficiency. The current network situation is evaluated by combining the device usage status and network performance index over a recent period.
[0031] S13. Determine the danger value of the device to be detected based on the network attack information.
[0032] Specifically, attack behavior is an important indicator of network security. Being attacked indicates network insecurity, and the more attacks a network receives, the less secure it is, and the greater the risk level of the device under test. When acquiring attack data (i.e., network attack information), it is appropriate to broaden the time frame, such as acquiring attack data from the most recent two months, which can improve the accuracy of the final intrusion detection. It is worth noting that the length of the time frame for acquiring parameters such as network attack information, device usage status, and network performance indicators should be determined by relevant security personnel based on the accuracy of intrusion detection, and no specific limit is set here.
[0033] S14. When the danger value is greater than the set danger threshold or the current network risk value is greater than the set situation threshold, an intrusion warning is initiated; wherein the current network risk value is positively correlated with the danger value and the current network situation, respectively.
[0034] Specifically, if the danger value AS is greater than the set danger threshold, or if the danger value AS is not greater than the set danger threshold, but the current network risk value calculated based on the danger value AS and the current network situation is greater than the set situation threshold, then the intrusion risk is considered high and an early warning is issued; otherwise, no early warning is issued. The set danger threshold and the set situation threshold are both empirical values, and their specific values are set according to the actual situation and are not limited here.
[0035] Compared with existing technologies, this implementation analyzes the current network situation based on device usage status and network performance indicators, and combines this with past network attack information to analyze the current network intrusion risk, so as to provide timely warnings when the intrusion risk is high, thus achieving the goal of timely warning before network intrusion occurs.
[0036] Furthermore, the current network risk value is equal to the product of the danger value and the current network situation;
[0037] Alternatively, the current network risk value can be calculated as follows: add a set deviation value to the current network situation, and then multiply it by the danger value to obtain the current network risk value; wherein the set deviation value is greater than zero.
[0038] Understandably, if the danger value AS exceeds the set danger threshold, it indicates that the device itself is at risk. In this case, regardless of the network situation, there is a risk of intrusion, thus requiring an alert. If the danger value AS is not greater than the set danger threshold, it means that the device itself is not at risk, but network risks can impact it. For example, if the network risk is high, even if the device itself is relatively secure, it may still be successfully attacked. Therefore, the device's danger value will be adjusted upwards based on the current network situation to obtain the current network risk value. For example, the current network risk value equals AS * (set deviation value + current network situation) or AS * current network situation. If the current network risk value is greater than the set situation threshold, it means that although the device itself is secure, it may be vulnerable to attack under the current network conditions, thus triggering an alarm. If the current network risk value is not greater than the set situation threshold, it means that the device can still operate safely under the current network conditions, and no alarm is triggered. The set deviation value can be 1, 2, 3, or 4, etc., without limitation.
[0039] It is worth noting that the calculation method for the current network risk value based on the hazard value and the current network situation is not limited to the specific example mentioned above. It can be set according to the actual situation, as long as the current network risk value is positively correlated with both the hazard value and the current network situation. For example, the current network risk value can be positively correlated with the product of the hazard value and the current network situation, or the sum of the current network risk value, hazard value, and current network situation, or other calculation methods. Preferably, the current network risk value is positively correlated with the product of the hazard value and the current network situation.
[0040] This implementation not only performs intrusion detection based on network attack situations, but also analyzes the current network situation based on device usage status and network performance indicators. If the combined situation of network attack situations and the current network situation meets the warning conditions, even if the current network attack situation is normal, it will be considered that there is an intrusion risk and a warning will be issued. This makes intrusion detection no longer solely dependent on abnormal information that has already occurred, but can also make predictions based on the network situation, ensuring the reliability and foresight of the warning.
[0041] In a preferred embodiment, the network attack information includes at least the total number of attacks, the number of attack types, and the attack duration, and the danger value of the device to be detected is positively correlated with the total number of attacks, the attack duration, and the number of attack types.
[0042] Specifically, network attack information can be obtained by retrieving attack logs from a recent period, and from these logs, the total number of attacks received (AN), the number of attack types (AY), and the duration of each attack (AT) can be retrieved. i Where i is the attack identifier. For example, if a device is recently infected by a worm virus and then subjected to a spoofing attack, then AY = 2. For any attack, the moment of attack is taken as the initial time, and the first time no attack is detected thereafter is taken as the end time of that attack. The duration of the attack is obtained by subtracting the initial time from the end time. The more attacks there are in total, the higher the risk value of the device under test; the longer the attack duration, the higher the risk value of the device under test; the more attack types, the higher the risk value of the device under test. The risk value of the device under test is calculated by combining the total number of attacks, the attack duration, and the attack types.
[0043] In one implementation, determining the danger level of the device to be detected based on the network attack information includes:
[0044] The dispersion of the attack duration and the average attack duration are calculated based on the attack duration of all attacks within the historical time period.
[0045] The danger value of the device under test is calculated based on the dispersion of the attack duration, the average attack duration, the total number of attacks, and the number of attack types; wherein the danger value of the device under test is positively correlated with the average attack duration, the total number of attacks, and the number of attack types, and negatively correlated with the dispersion of the attack duration.
[0046] Understandably, a longer average attack duration and a higher total number of attacks indicate more frequent attacks on the device, thus increasing the risk level of the device under test. A greater number of attack types indicates more complex attacks, further increasing the risk level of the device under test. Conversely, a greater dispersion in attack duration indicates irregular attack patterns, resulting in a lower risk level for the device under test.
[0047] In one implementation, calculating the danger value of the device under test based on the dispersion of the attack duration, the average attack duration, the total number of attacks, and the number of attack types includes:
[0048] Divide the difference between the average attack duration and the minimum attack duration by the difference between the maximum attack duration and the minimum attack duration to obtain the normalized value of the average duration.
[0049] The danger value of the device under test is obtained by multiplying the average duration normalized value, the number of attack types, and the total number of attacks, and then dividing by the dispersion of the attack duration.
[0050] For example, determining the objectively existing risk level of the device under test based on historical cyberattack information:
[0051]
[0052] Where AS is the hazard value, σ AT AT for all attack durations i The standard deviation. i {AT i} represents the average attack duration of each attack, min i {AT i} represents the minimum duration of each attack, and max represents the minimum duration of each attack. i {AT i} represents the maximum duration of each attack. This is the normalized value of the average attack duration over a recent period (i.e., the average duration normalized value). A larger value indicates a longer attack duration and greater danger; AS is directly proportional to AT. AY represents the number of attack types received; a larger value indicates greater danger, and AS is directly proportional to AT. σ ATThis represents the difference between different durations, used to characterize the dispersion of attack duration. A larger value indicates an irregular attack duration, and the risk is lower compared to a regular attack. AS and σ AT Inversely proportional.
[0053] It is worth noting that the dispersion of attack duration is not limited to the specific calculation methods mentioned above. Variance and other methods can also be used to characterize the dispersion of attack duration, without specific limitations here. The specific calculation formula for the danger value is not limited to the specific calculation methods mentioned above. A specific calculation formula can be set according to the actual situation, as long as the danger value is positively correlated with the average attack duration, the total number of attacks, and the number of attack types, and negatively correlated with the dispersion of attack duration.
[0054] In a preferred embodiment, the device usage status includes at least CPU utilization, and the network performance indicators include at least bandwidth, network speed, and traffic data.
[0055] The calculation of the current network situation based on the device usage status and the network performance indicators includes:
[0056] The state value of the minimum time period is calculated based on the network speed, CPU utilization, and bandwidth within the minimum time period; the state value is positively correlated with the network speed and the bandwidth, and negatively correlated with the CPU utilization; the historical time period is divided into several minimum time periods;
[0057] The state dispersion is calculated based on all the state values within the historical time period, and the network impact value is calculated based on the state dispersion and the total number of state values.
[0058] Based on the traffic data, analyze the uplink and downlink traffic change trends between the device under test and each interactive device, and calculate the data impact value based on the uplink and downlink traffic change trends of the device under test.
[0059] The current network situation is calculated based on the network impact value and the data impact value.
[0060] Specifically, device usage status includes CPU utilization, which characterizes the CPU resource utilization of the device under test. Device usage status can also include memory utilization or disk utilization, etc. Memory utilization characterizes the memory resource utilization of the device under test, and disk utilization characterizes the disk resource utilization of the device under test. The status values are negatively correlated with CPU utilization, memory utilization, and disk utilization, respectively. Network performance indicators include bandwidth, network speed, and traffic data. Traffic data can be data packets. Network performance indicators characterize network status. The following is a brief introduction to these parameters:
[0061] 1. CPU utilization, bandwidth, network speed
[0062] Increased CPU utilization can indicate network risks. For example, during a Distributed Denial of Service (DDoS) attack, attackers send a large number of requests simultaneously through multiple controllers, overwhelming the device under test and causing a significant increase in CPU utilization due to the large volume of requests. Therefore, CPU utilization is used as a detection metric.
[0063] Similarly, bandwidth and network speed can also be used to detect network risks. For example, during a DDoS attack, a large number of requests can exhaust bandwidth, preventing the system from processing requests normally and thus interrupting service. Therefore, bandwidth and network speed are used as detection data.
[0064] CPU utilization, bandwidth, and network speed are three parameters that change dynamically. Therefore, the three parameters obtained are all in the form of sequences, and each sequence includes X elements.
[0065] Taking CPU utilization as an example, CPU utilization is: CPU = {CPU1, CPU2, ..., CPU} x}
[0066] The method for determining this element is as follows:
[0067] 1) Divide the detection period into X equal parts, that is, divide the historical period into X minimum time periods;
[0068] 2) For time period i, obtain the average CPU utilization during that time period. i .
[0069] 2. Data packet
[0070] Data packets are used to represent traffic data. Specifically, data packets reflect network traffic; the more data packets, the greater the network traffic. Network traffic can be used to perceive network risks. For example, during a DDoS attack, attackers may send a large number of request packets simultaneously through multiple controllers, which will significantly increase network traffic.
[0071] The data packets are obtained from the traffic logs over a recent period. The data packets include uplink traffic data packets and downlink traffic data packets. Uplink traffic data packets exist in the form of a triple [destination IP, packet size, sending time], while downlink traffic data packets exist in the form of a triple [source IP, packet size, received data].
[0072] Specifically, the current network situation is calculated as follows:
[0073] 1. Construct a detection data matrix from CPU utilization, bandwidth, and network speed.
[0074] CPU utilization, bandwidth, and network speed are all calculated by dividing the detection period into X equal parts, with each part corresponding to a minimum time period, resulting in X value sequences. A matrix is then constructed based on these three parameters as shown below:
[0075]
[0076] Wherein, CPU1 represents the CPU utilization corresponding to the first part, WB1 represents the bandwidth corresponding to the first part, and IS1 represents the network speed corresponding to the first part. x For the CPU utilization corresponding to the xth part, WB x For the bandwidth corresponding to the xth segment, IS x The network speed corresponding to the xth part.
[0077] Additionally, to improve data comparability, the values in this matrix can also be normalized values, such as the matrix below:
[0078]
[0079] Wherein, minCPU is the minimum CPU utilization of all instances, and maxCPU is the maximum CPU utilization of all instances. minWB is the minimum bandwidth of all instances, and maxWB is the maximum bandwidth of all instances. minIS is the minimum network rate of all instances, and maxIS is the maximum network speed of all instances.
[0080] 2. Determine the status value of each column based on the value of each column.
[0081] Specifically, the state value of the minimum time period is calculated in the following way:
[0082] Multiply the bandwidth within the minimum time period by the network speed within the minimum time period, and then divide by the CPU utilization within the minimum time period to obtain the state value of the minimum time period.
[0083] Starting from the first column of the matrix, select one column of data at a time, for example, select the first column containing CPU1, WB1, and IS1. The state value of this column is:
[0084] For example, selecting the data in column x (CPU) x WB x and IS x The status value of this column is:
[0085] The status value represents the device's state, specifically its security status. Higher CPU utilization indicates a greater vulnerability to attack and a lower security level. x With ST x Inversely proportional. The lower the bandwidth and network speed, the greater the vulnerability to attack and the worse the security. WB x and IS x Both are related to ST x Proportional.
[0086] It is worth noting that the calculation method of the status value is not limited to the specific formula mentioned above. It can be set according to the actual situation and is not limited here, but the following conditions must be met: the status value is positively correlated with network speed and bandwidth, and the status value is negatively correlated with CPU utilization.
[0087] 3. Calculate the network influence value W
[0088] The degree of state dispersion is calculated based on all the calculated state values. This dispersion can be characterized by parameters such as standard deviation and variance, which are not limited here. Then, the network influence value W is calculated based on the degree of state dispersion and the total number of state values. It is worth noting that the greater the degree of state dispersion, the greater the network influence value; conversely, the greater the total number of state values, the smaller the network influence value. Understandably, the total number of state values is X.
[0089] 4. Calculate the data influence value D
[0090] First, the data packets are classified into uplink and downlink data. For uplink data packets (i.e., uplink traffic data packets), the data is classified according to the destination IP address. For downlink data packets (i.e., downlink traffic data packets), the data is classified according to the source IP address. After the above two classifications, the uplink and downlink traffic change trends between the device under test and the interactive devices corresponding to each IP address are analyzed. The data impact value D is calculated by combining the uplink and downlink traffic change trends.
[0091] 5. Calculate the current network situation based on the network influence value W and the data influence value D; for example, multiply the network influence value W and the data influence value D to obtain the current network situation. It is worth noting that the calculation method for the current network situation is not limited to the specific example above. The calculation formula can be designed according to the actual situation, but the following conditions must be met: the current network situation is positively correlated with the network influence value W and the data influence value D, respectively.
[0092] In a preferred embodiment, the data impact value is calculated in the following manner:
[0093] The uplink traffic data packets of the device under test are categorized according to their destination IP addresses, and the downlink traffic data packets of the device under test are categorized according to their source IP addresses; wherein, the traffic data of the device under test includes the uplink traffic data packets and the downlink traffic data packets;
[0094] Determine the sending and receiving times of all data packets for each type of IP address within the historical time period, form a target time period for each type of IP address based on the sending and receiving times, and calculate the number of data packets per unit duration for each type of IP address within the target time period;
[0095] For each type of IP address, obtain the number of data packets per unit duration within a first preset time period before the target time period, and obtain the number of data packets per unit duration within a second preset time period after the target time period;
[0096] Calculate the first traffic change trend of the number of data packets per unit duration between the first preset time period before the target time period and the target time period, and calculate the second traffic change trend of the number of data packets per unit duration between the target time period and the second preset time period after the target time period;
[0097] The first quantity, the second quantity, and the third quantity are counted separately; wherein, the first quantity is the number of IP addresses whose first traffic change trend is consistent with the second traffic change trend, the second quantity is the number of IP addresses whose first traffic change trend is opposite to the second traffic change trend, and the third quantity is the number of IP addresses whose first traffic change trend or second traffic change trend has no significant change.
[0098] The data impact value is calculated based on the first quantity, the second quantity, and the third quantity; wherein the data impact value is positively correlated with the second quantity and the third quantity, and negatively correlated with the first quantity.
[0099] Specifically, the data impact value is calculated as follows:
[0100] (1) Each data packet carries a destination IP address and a source IP address. First, the data packets are divided into uplink traffic data packets and downlink traffic data packets. Then, the uplink traffic data packets are classified according to the destination IP address, and the downlink data packets are classified according to the source IP address.
[0101] (2) Parse the data packets. For each type of data packet obtained in step (1), form a target time period based on the sending time involved.
[0102] The start time of this target time period is the earliest time of transmission for the corresponding category of data packets, and the end time is the latest time of reception for the corresponding category of data packets.
[0103] (3) For each type of data packet, determine the total number of data packets in the first preset time period ΔT1 before the earliest time, and the total number of data packets in the second preset time period ΔT2 after the latest time.
[0104] ΔT1 and ΔT2 are preset time periods. These preset time periods can be included within the time period for acquiring detection data (i.e., within the historical time period), partially included within the time period for acquiring detection data, or outside the time period for acquiring detection data.
[0105] Considering that data transmission from an IP address is not necessarily a single continuous transmission, but can also be multiple non-continuous transmissions, the target time period formed in step (2) only obtains the transmission behavior within the most recent period, and may not be all the transmission behavior of that IP. Therefore, based on this, we will extend forward and backward by ΔT1 and ΔT2 to obtain the data transmission situation for all extended durations, so as to obtain as completely as possible all the data packets of a single transmission behavior of an IP address, and ensure the accuracy of subsequent intrusion detection.
[0106] The durations of ΔT1 and ΔT2 are set by relevant personnel and can be determined based on the monitoring accuracy. The higher the accuracy, the larger ΔT1 and ΔT2 will be, and the stronger the integrity of the acquired data will be.
[0107] In addition, the values of ΔT1 and ΔT2 can be the same or different, which can be set by the user.
[0108] This results in three time periods for each type of data packet, representing the total number of data packets in the first ΔT1 time period. (i.e., the total number of data packets in the left adjacent time period), the total number of data packets in the subsequent ΔT2. (i.e., the total number of data packets in the right adjacent time period), target time period T j Data packet size Where j is the IP address identifier.
[0109] (4) For each type of data packet, calculate
[0110] This represents the number of data packets per unit time in the first ΔT1. The number of data packets per unit duration within the target time period. This represents the number of data packets per unit duration after ΔT2.
[0111] This represents the change in the total number of data packets per unit time in the preceding ΔT period compared to the change in the number of data packets per unit time during the time period covered by the data, i.e., the first trend of traffic change. This represents the change in the number of data packets per unit time within the time period covered by the data, compared to the total number of data packets per unit time after ΔT, i.e., the second traffic trend. ε is a preset minimum value, set to prevent the denominator from being 0.
[0112] This shows the trend of the total number of data packets for the j-th IP address. If the number is positive, the flow rate trend is consistent. If the value is negative, the trend of flow change changes. 0 or If the value is infinity, it means that the absolute value of either the first or second flow rate trend is less than the set low threshold, indicating that there is a direction with little change.
[0113] It is worth noting that, The specific calculation method is not limited to the above formula; other methods can also be used, as long as it ensures... It is sufficient to reflect, to a certain extent, whether the trend of traffic changes is consistent and whether there are significant changes in the first and second traffic change trends.
[0114] (5) Statistics The number of positive numbers (i.e., the first quantity) The number of negative numbers (i.e., the second quantity), and The data influence value is calculated based on the first, second, and third quantities, which are 0 and infinity (i.e., the third quantity).
[0115] Further, the step of calculating the data impact value based on the first quantity, the second quantity, and the third quantity includes: adding the second quantity and the third quantity and then dividing by the first quantity to obtain the data impact value.
[0116] Specifically, the formula for calculating the data impact value D is as follows:
[0117]
[0118] in, For all destination IP addresses and all source IP addresses, The total number of negative numbers. For all destination IP addresses and all source IP addresses, The total number of positive numbers. For all destination IP addresses and all source IP addresses, The total number that is 0 or infinite.
[0119] It is understandable that the data impact value is the degree of impact on network security from the perspective of data packets; the larger the value, the greater the impact. The specific formula for calculating the data impact value is not limited to the formula mentioned above and can be set according to the actual situation. For example, it is necessary to ensure that the data impact value is positively correlated with the second and third quantities, and negatively correlated with the first quantity.
[0120] In a preferred embodiment, calculating the network impact value based on the state dispersion and the total number of state values includes: when the average value of the data packets is not greater than a set minimum threshold or is greater than or equal to a set maximum threshold, calculating the network impact value based on the total number of data packets, the state dispersion, and the total number of state values; wherein the network impact value is positively correlated with the total number of data packets and the state dispersion, respectively, and negatively correlated with the total number of state values;
[0121] When the average value of the data packets is greater than the set minimum threshold and less than the set maximum threshold, the network impact value is calculated based on the state dispersion and the total number of state values; wherein, the network impact value is positively correlated with the state dispersion and negatively correlated with the total number of state values.
[0122] Furthermore, the network influence value is calculated in the following manner:
[0123] When the average value of the data packets is not greater than a preset minimum threshold or not less than a preset maximum threshold, the network impact value is obtained by dividing the state dispersion by the cube root of the total number of state values and then multiplying it by the total number of data packets.
[0124] When the average value of the data packets is between the preset minimum threshold and the preset maximum threshold, the network impact value is obtained by dividing the state dispersion by the cube root of the total number of state values.
[0125] For example, assuming a minimum threshold of 64 bytes and a maximum threshold of 1518 bytes are set, the network impact value W is calculated as follows:
[0126] like byte or but
[0127] like but
[0128] in, State value STi The mean, P u P represents the average size of the uplink traffic data packets (i.e., the average value of the uplink traffic data packets). d This represents the average size of downlink traffic data packets (i.e., the average value of downlink traffic data packets).
[0129] The value represents the cube difference of all state values. This value indicates the degree of difference (i.e., dispersion) between state values. The greater the degree of difference, the greater the fluctuation of the device state in the previous period, which has a greater impact on the network. The smaller the degree of difference, the more stable the device state in the previous period, which has a smaller impact on the network.
[0130] n D The total number of data packets, (P) u +P d ) / 2 is the average size of the data packet. Normally, the average size of a data packet is between 64 bytes and 1518 bytes. If it is less than 64 bytes, it indicates a possible fragmentation attack. Therefore, n D The larger the value, the greater the impact on the network. If it is not less than 1518 bytes, it indicates a potential attack involving extremely large data packets; therefore, n... D The larger it is, the greater its impact on the network.
[0131] It's worth noting that the network impact value is the degree of influence on network security derived from network-related detection data; the higher the value, the greater the impact. The specific calculation method for the network impact value is not limited to the formula mentioned above and can be set according to the actual situation.
[0132] Compared with existing technologies, the method provided in this invention first acquires network attack information, device usage status, and network performance indicators of the device under test within a historical time period; then, it calculates the current network situation based on the device usage status and network performance indicators, and determines the danger value of the device under test based on the network attack information; finally, it initiates an intrusion warning when the danger value exceeds a set danger threshold or the current network risk value exceeds a set situation threshold; wherein, the current network risk value is positively correlated with both the danger value and the current network situation. Therefore, this invention analyzes the current network situation based on device usage status and network performance indicators, and combines this with past network attack information to analyze the current network intrusion risk, enabling timely warnings when the intrusion risk is high, thus achieving the goal of timely warning before a network intrusion occurs.
[0133] See Figure 2 This invention also provides a network intrusion detection device, comprising:
[0134] Information acquisition module 21 is used to acquire network attack information, device usage status and network performance indicators of the device under test within a historical time period;
[0135] Network situation calculation module 22 is used to calculate the current network situation based on the device usage status and the network performance indicators;
[0136] The danger value calculation module 23 is used to determine the danger value of the device to be detected based on the network attack information;
[0137] The early warning module 24 is used to initiate an intrusion warning when the danger value is greater than a set danger threshold or the current network risk value is greater than a set situation threshold; wherein the current network risk value is positively correlated with the danger value and the current network situation, respectively.
[0138] In one implementation, the network attack information includes at least the total number of attacks, the number of attack types, and the attack duration, and the danger value of the device to be detected is positively correlated with the total number of attacks, the attack duration, and the number of attack types.
[0139] In one embodiment, the hazard value calculation module 23 is specifically used for:
[0140] The dispersion of the attack duration and the average attack duration are calculated based on the attack duration of all attacks within the historical time period.
[0141] The danger value of the device under test is calculated based on the dispersion of the attack duration, the average attack duration, the total number of attacks, and the number of attack types; wherein the danger value of the device under test is positively correlated with the average attack duration, the total number of attacks, and the number of attack types, and negatively correlated with the dispersion of the attack duration.
[0142] In one implementation, calculating the danger value of the device under test based on the dispersion of the attack duration, the average attack duration, the total number of attacks, and the number of attack types includes:
[0143] Divide the difference between the average attack duration and the minimum attack duration by the difference between the maximum attack duration and the minimum attack duration to obtain the normalized value of the average duration.
[0144] The danger value of the device under test is obtained by multiplying the average duration normalized value, the number of attack types, and the total number of attacks, and then dividing by the dispersion of the attack duration.
[0145] In one implementation, the device usage status includes at least CPU utilization, and the network performance indicators include at least bandwidth, network speed, and traffic data.
[0146] The network situation calculation module 22 is specifically used for:
[0147] The status value of the minimum time period is calculated based on the network speed, CPU utilization, and bandwidth within the minimum time period; wherein, the historical time period is divided into several minimum time periods, and the status value is positively correlated with the network speed and the bandwidth, and negatively correlated with the CPU utilization.
[0148] The state dispersion is calculated based on all the state values within the historical time period, and the network impact value is calculated based on the state dispersion and the total number of state values.
[0149] Based on the traffic data, analyze the uplink and downlink traffic change trends between the device under test and each interactive device, and calculate the data impact value based on the uplink and downlink traffic change trends of the device under test.
[0150] The current network situation is calculated based on the network impact value and the data impact value.
[0151] In one implementation, the state value of the minimum time period is calculated in the following manner:
[0152] Multiply the bandwidth within the minimum time period by the network speed within the minimum time period, and then divide by the CPU utilization within the minimum time period to obtain the status value of the minimum time period.
[0153] The network impact value is calculated in the following way:
[0154] When the average value of the data packets is not greater than a preset minimum threshold or not less than a preset maximum threshold, the network impact value is obtained by dividing the state dispersion by the cube root of the total number of state values and then multiplying it by the total number of data packets.
[0155] When the average value of the data packets is between the preset minimum threshold and the preset maximum threshold, the network impact value is obtained by dividing the state dispersion by the cube root of the total number of state values.
[0156] The current network situation is calculated by multiplying the network influence value and the data influence value.
[0157] In one implementation, the data impact value is calculated in the following manner:
[0158] The uplink traffic data packets of the device under test are categorized according to their destination IP addresses, and the downlink traffic data packets of the device under test are categorized according to their source IP addresses; wherein, the traffic data of the device under test includes the uplink traffic data packets and the downlink traffic data packets;
[0159] Determine the sending and receiving times of all data packets for each type of IP address within the historical time period, form a target time period for each type of IP address based on the sending and receiving times, and calculate the number of data packets per unit duration for each type of IP address within the target time period;
[0160] For each type of IP address, obtain the number of data packets per unit duration within a first preset time period before the target time period, and obtain the number of data packets per unit duration within a second preset time period after the target time period;
[0161] Calculate the first traffic change trend of the number of data packets per unit duration between the first preset time period before the target time period and the target time period, and calculate the second traffic change trend of the number of data packets per unit duration between the target time period and the second preset time period after the target time period;
[0162] The first quantity, the second quantity, and the third quantity are counted separately; wherein, the first quantity is the number of IP addresses whose first traffic change trend is consistent with the second traffic change trend, the second quantity is the number of IP addresses whose first traffic change trend is opposite to the second traffic change trend, and the third quantity is the number of IP addresses whose first traffic change trend or second traffic change trend has no significant change.
[0163] The data impact value is calculated based on the first quantity, the second quantity, and the third quantity; wherein the data impact value is positively correlated with the second quantity and the third quantity, and negatively correlated with the first quantity.
[0164] In one implementation, calculating the data impact value based on the first quantity, the second quantity, and the third quantity includes:
[0165] The data impact value is obtained by adding the second quantity and the third quantity together and then dividing by the first quantity.
[0166] In one implementation, the current network risk value is equal to the product of the danger value and the current network situation;
[0167] Alternatively, the current network risk value can be calculated as follows: add a set deviation value to the current network situation, and then multiply it by the danger value to obtain the current network risk value; wherein the set deviation value is greater than zero.
[0168] It is worth noting that the working principle of the network intrusion detection device provided in the above embodiments can be found in the workflow of the network intrusion detection method provided in any of the above embodiments, and will not be repeated here.
[0169] Compared with existing technologies, the network intrusion detection device provided in this embodiment of the invention first acquires network attack information, device usage status, and network performance indicators of the device to be detected within a historical time period; then, it calculates the current network situation based on the device usage status and the network performance indicators, and determines the danger value of the device to be detected based on the network attack information; finally, it initiates an intrusion warning when the danger value exceeds a set danger threshold or the current network risk value exceeds a set situation threshold; wherein, the current network risk value is positively correlated with both the danger value and the current network situation. Therefore, this embodiment of the invention analyzes the current network situation based on device usage status and network performance indicators, and combines this with past network attack information to analyze the current network intrusion risk, enabling timely warnings when the intrusion risk is high, thus achieving the goal of timely warning before a network intrusion occurs.
[0170] This invention also provides a data security product, which is a data center. The data center includes a data sharing service layer, and the network intrusion detection method described in any of the above embodiments is applied to the data sharing security function module of the data sharing service layer.
[0171] Alternatively, the data security product is a data platform, which is used to execute the network intrusion detection method as described in any of the above embodiments;
[0172] Alternatively, the data security product may be a capability sharing platform, which is used to execute the network intrusion detection method as described in any of the above embodiments. Optionally, the capability sharing platform may be a general-purpose capability sharing platform.
[0173] For example, suppose the data security product is a secure data center applied in the field of China Mobile Information Technology (IT). The architecture of the secure data center includes a data sharing service layer, which has data sharing security functions. These functions are implemented by a data sharing security function module. The network intrusion detection method described in any of the above embodiments is executed by the data sharing security function module. The secure data center is a unified platform for the collection and aggregation of secure data, including a data collection layer, a data preprocessing layer, a data storage and computing layer, a data development layer, a data mart layer, and a data sharing service layer. It can realize centralized operation and internal sharing of secure data. When the secure data center receives a request from a user to share secure data, it determines whether to share the secure data with the user based on the user's level and the value of the requested secure data.
[0174] See Figure 3 This invention also provides a network intrusion detection device, including a processor 31, a memory 32, and a computer program stored in the memory 32 and configured to be executed by the processor 31. When the processor 31 executes the computer program, it implements the steps described in the network intrusion detection method embodiments above, for example... Figure 1 S11 to S14 in the above-mentioned device embodiments; or, when the processor 31 executes the computer program, it implements the functions of each module.
[0175] For example, the computer program can be divided into one or more modules, which are stored in the memory 32 and executed by the processor 31 to complete the present invention. The one or more modules can be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the network intrusion detection device. For example, the computer program can be divided into multiple modules. The specific working process of each module can be referred to the working process of the network intrusion detection device described in the above embodiments, and will not be repeated here.
[0176] The network intrusion detection device can be a desktop computer, laptop, handheld computer, or cloud server, etc. The network intrusion detection device may include, but is not limited to, a processor 31 and a memory 32. Those skilled in the art will understand that the network intrusion detection device may also include input / output devices, network access devices, buses, etc.
[0177] The processor 31 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor. The processor 31 is the control center of the network intrusion detection device, connecting various parts of the device via various interfaces and lines.
[0178] The memory 32 can be used to store the computer programs and / or modules. The processor 31 implements various functions of the network intrusion detection device by running or executing the computer programs and / or modules stored in the memory 32 and calling the data stored in the memory 32. The memory 32 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as image playback function), etc.; the data storage area may store data created based on the use of the mobile phone, etc. In addition, the memory 32 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0179] If the integrated modules of the network intrusion detection device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by the processor 31, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0180] This invention also provides a computer program product, including a computer program / instructions, which, when executed by a processor, implement the network intrusion detection method as described in any of the above embodiments.
[0181] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A network intrusion detection method, characterized in that, include: Obtain network attack information, device usage status, and network performance indicators of the device under test within a historical time period; Calculate the current network situation based on the device usage status and the network performance indicators; The danger level of the device to be detected is determined based on the network attack information. An intrusion warning is initiated when the danger value exceeds a set danger threshold or the current network risk value exceeds a set situation threshold; wherein, the current network risk value is positively correlated with the danger value and the current network situation, respectively; the network attack information includes at least the total number of attacks, the number of attack types, and the attack duration, and the danger value of the device to be detected is positively correlated with the total number of attacks, the attack duration, and the number of attack types, respectively; The device usage status includes CPU utilization, memory utilization, and disk utilization; the network performance indicators include at least bandwidth, network speed, and traffic data. Determining the danger level of the device to be detected based on the network attack information includes: The difference between the average attack duration and the minimum attack duration is divided by the difference between the maximum attack duration and the minimum attack duration to obtain the normalized value of the average duration. The danger value of the device under test is obtained by multiplying the average duration normalized value, the number of attack types and the total number of attacks, and then dividing by the dispersion of the attack duration. The average attack duration and the dispersion of the attack duration are calculated based on the attack duration of all attacks within the historical time period.
2. The network intrusion detection method as described in claim 1, characterized in that, Determining the danger level of the device to be detected based on the network attack information includes: The dispersion of the attack duration and the average attack duration are calculated based on the attack duration of all attacks within the historical time period. The danger value of the device under test is calculated based on the dispersion of the attack duration, the average attack duration, the total number of attacks, and the number of attack types; wherein the danger value of the device under test is positively correlated with the average attack duration, the total number of attacks, and the number of attack types, and negatively correlated with the dispersion of the attack duration.
3. The network intrusion detection method as described in claim 1, characterized in that, The device usage status includes at least CPU utilization, and the network performance indicators include at least bandwidth, network speed, and traffic data. The calculation of the current network situation based on the device usage status and the network performance indicators includes: The state value of the minimum time period is calculated based on the network speed, CPU utilization, and bandwidth within the minimum time period; the state value is positively correlated with the network speed and the bandwidth, and negatively correlated with the CPU utilization; the historical time period is divided into several minimum time periods; The state dispersion is calculated based on all the state values within the historical time period, and the network impact value is calculated based on the state dispersion and the total number of state values. Based on the traffic data, analyze the uplink and downlink traffic change trends between the device under test and each interactive device, and calculate the data impact value based on the uplink and downlink traffic change trends of the device under test. The current network situation is calculated based on the network impact value and the data impact value.
4. The network intrusion detection method as described in claim 3, characterized in that, The state value for the minimum time period is calculated in the following way: Multiply the bandwidth within the minimum time period by the network speed within the minimum time period, and then divide by the CPU utilization within the minimum time period to obtain the status value of the minimum time period. The network impact value is calculated in the following way: When the average value of the data packets is not greater than a preset minimum threshold or not less than a preset maximum threshold, the network impact value is obtained by dividing the state dispersion by the cube root of the total number of state values and then multiplying it by the total number of data packets. When the average value of the data packets is between the preset minimum threshold and the preset maximum threshold, the network impact value is obtained by dividing the state dispersion by the cube root of the total number of state values. The current network situation is calculated by multiplying the network influence value and the data influence value.
5. The network intrusion detection method as described in claim 3, characterized in that, The data impact value is calculated in the following way: The uplink traffic data packets of the device under test are categorized according to their destination IP addresses, and the downlink traffic data packets of the device under test are categorized according to their source IP addresses; wherein, the traffic data of the device under test includes the uplink traffic data packets and the downlink traffic data packets; Determine the sending and receiving times of all data packets for each type of IP address within the historical time period, form a target time period for each type of IP address based on the sending and receiving times, and calculate the number of data packets per unit duration for each type of IP address within the target time period; For each type of IP address, obtain the number of data packets per unit duration within a first preset time period before the target time period, and obtain the number of data packets per unit duration within a second preset time period after the target time period; Calculate the first traffic change trend of the number of data packets per unit duration between the first preset time period before the target time period and the target time period, and calculate the second traffic change trend of the number of data packets per unit duration between the target time period and the second preset time period after the target time period; The first quantity, the second quantity, and the third quantity are counted separately; wherein, the first quantity is the number of IP addresses whose first traffic change trend is consistent with the second traffic change trend, the second quantity is the number of IP addresses whose first traffic change trend is opposite to the second traffic change trend, and the third quantity is the number of IP addresses whose first traffic change trend or second traffic change trend has no significant change. The data impact value is calculated based on the first quantity, the second quantity, and the third quantity; wherein the data impact value is positively correlated with the second quantity and the third quantity, and negatively correlated with the first quantity.
6. The network intrusion detection method as described in claim 5, characterized in that, The step of calculating the data impact value based on the first quantity, the second quantity, and the third quantity includes: The data impact value is obtained by adding the second quantity and the third quantity together and then dividing by the first quantity.
7. A network intrusion detection device, characterized in that, include: The information acquisition module is used to acquire network attack information, device usage status and network performance indicators of the device under test within a historical time period. The network situation calculation module is used to calculate the current network situation based on the device usage status and the network performance indicators. A danger value calculation module is used to determine the danger value of the device to be detected based on the network attack information. The early warning module is used to initiate an intrusion warning when the danger value exceeds a set danger threshold or the current network risk value exceeds a set situation threshold; wherein the current network risk value is positively correlated with the danger value and the current network situation, respectively. The device usage status includes CPU utilization, memory utilization, and disk utilization; the network performance indicators include at least bandwidth, network speed, and traffic data. The network attack information includes at least the total number of attacks, the number of attack types, and the attack duration. The danger value of the device under test is positively correlated with the total number of attacks, the attack duration, and the number of attack types, respectively. The hazard value calculation module is specifically used for: The difference between the average attack duration and the minimum attack duration is divided by the difference between the maximum attack duration and the minimum attack duration to obtain the normalized value of the average duration. The danger value of the device under test is obtained by multiplying the average duration normalized value, the number of attack types, and the total number of attacks, and then dividing by the dispersion of the attack duration; wherein, the average attack duration and the dispersion of the attack duration are calculated based on the attack duration of all attacks within the historical time period.
8. A data security product, characterized in that, The data security product is a data center, which includes a data sharing service layer. The network intrusion detection method as described in any one of claims 1 to 6 is applied to the data sharing security function module of the data sharing service layer. Alternatively, the data security product is a data platform, which is used to execute the network intrusion detection method as described in any one of claims 1 to 6; Alternatively, the data security product may be a capability sharing platform, which is used to execute the network intrusion detection method as described in any one of claims 1 to 6.
9. A network intrusion detection device, characterized in that, The method includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the network intrusion detection method as described in any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device on which the computer-readable storage medium is located to perform the network intrusion detection method as described in any one of claims 1 to 6.
11. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the network intrusion detection method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Network security situation assessment method and device, equipment and storage medium
CN118802195A