A method for real-time perception and coordinated handling of network security situation
By analyzing the test question download log, building a behavior model, and implementing three-level isolation measures in the sandbox environment, the problem of indistinguishable compliance and non-compliance test question download behavior in the campus network is solved, and intelligent monitoring and security protection of test question download behavior is realized.
Patent Information
- Application Number
- CN202510177702.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-18
AI Technical Summary
In campus networks, the data characteristics of compliance and non-compliant test questions may have great similarity, making it difficult to effectively distinguish rules-based identification methods, and traditional abnormal behavior detection methods are difficult to deal with various technical means to break through the security boundaries of the sandbox environment.
By obtaining and analyzing the test questions download logs, extracting user behavior characteristics, building a compliance and abnormal behavior model, and establishing a three-level isolated test questions resource access sandbox environment, including identity and course-based permission control, dynamic download threshold limits, and behavior monitoring probes.
It realizes intelligent monitoring and security protection of campus online test questions download behavior, effectively prevents the risk of test questions leaks, and can promptly discover and prevent non-compliant large-scale test questions download behaviors while ensuring compliance and cross-curricular test questions download behaviors.
Smart Images

Figure CN119652684B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular to a method for real-time perception and coordinated handling of network security situations. Background Art
[0002] On campus, in order to ensure that students can download test questions across courses in compliant scenarios such as review week and teaching seminars, and can also effectively identify and prevent large-scale test question downloading behaviors in non-compliant scenarios such as exam week, it is necessary to build a real-time security situation perception system based on the sandbox mechanism. However, in the process of achieving this goal, there is a key technical contradiction: how to ensure that the compliant cross-course test question downloading behaviors are not affected when accessing the relevant course groups in the teaching seminar and review phases that are closely related to the courses, while also timely discovering and preventing non-compliant large-scale test question downloading behaviors. The core of this contradiction lies in the fact that the compliant and non-compliant test question downloading behaviors may have great similarities in data characteristics, making it difficult for rule-based identification methods to effectively distinguish them. At the same time, the data formats and structures of test questions in different courses may be different, which further increases the difficulty of identification. In addition, in non-compliant scenarios, a large number of students may use a variety of technical means to break through the security boundaries of the sandbox environment, making it difficult for traditional abnormal behavior detection methods to work. Therefore, it is urgent to explore a lightweight, efficient, and accurate cross-sandbox collaboration mechanism to detect potential security threats in a timely manner. Summary of the invention
[0003] The present invention provides a method for real-time perception and coordinated handling of network security situation, which mainly includes:
[0004] Obtain the test question download logs from the campus network, extract the download time, user identity, course information and download volume from the download logs, discretize the extracted data, and form a scattered batch initial behavior data set;
[0005] Identify download scenarios based on the initial behavior data set. Download scenarios include compliant scenarios and non-compliant scenarios. Compliant scenarios include accessing related course groups across courses during teaching seminars and review stages. Non-compliant scenarios include sudden download peaks and exam-sensitive periods, repeatedly switching between question banks of different courses, and analyzing download entrances, access sources, and access times. Generate a scenario classification data set based on the relevant data of download scenarios in different time periods.
[0006] A clustering algorithm is used to analyze the download behavior of compliance scenarios in the scenario classification dataset. By extracting the behavioral characteristics of students accessing cross-course related course groups during the teaching discussion and review stages, a compliance behavior feature model that describes the normal download frequency and reasonable user distribution is obtained.
[0007] Obtain anonymous download accounts for non-compliant scenarios, use anomaly detection algorithms to identify behaviors that deviate from the compliant behavior feature model, and if the download volume increases suddenly during the sensitive exam period, the user identity is single and concentrated, and the user repeatedly switches between question banks of different courses, the download behavior is judged to be abnormal download, and the behavioral features of the abnormal download behavior are extracted to generate an abnormal behavior feature model;
[0008] The pre-built sandbox environment is monitored in real time based on the abnormal behavior feature model. If an anonymous download account is detected to have a sudden increase in downloads during the sensitive exam period, or to frequently cross-compare test questions across courses, it is determined that a sandbox boundary breach warning has been triggered, and a warning signal is generated;
[0009] Analyze warning signals and sandbox environment security logs. If resource usage increases suddenly, permissions change frequently, or network traffic surges, it is determined that the sandbox boundary has been maliciously breached, and the breach feature analysis results are obtained.
[0010] Dynamically adjust the sandbox security policy based on the breakthrough feature analysis results, including restricting the download permissions of abnormal anonymous accounts, isolating surging malicious traffic, and optimizing the allocation of suddenly increased resources. Apply the dynamically adjusted sandbox security policy to the sandbox.
[0011] The technical solution provided by the embodiment of the present invention may have the following beneficial effects:
[0012] The present invention discloses a method for real-time perception and collaborative disposal of network security situation. The method extracts user behavior characteristics by analyzing download logs and constructs compliance and abnormal behavior models. On this basis, a three-level isolated test resource access sandbox environment is established, including identity-based and course-based permission control, dynamic download threshold restrictions, and behavior monitoring probes. When abnormal behaviors such as frequent downloads and cross-comparison of cross-course test questions by anonymous accounts during sensitive periods are detected, a sandbox boundary breach warning is triggered. Subsequently, the warning signal and security log are analyzed through a collaborative disposal algorithm to determine whether the sandbox has been maliciously breached. Finally, the security policy is dynamically adjusted according to the analysis results, such as limiting abnormal account permissions, isolating malicious traffic, etc. The present invention realizes intelligent monitoring and security protection of campus network test question downloading behavior, and effectively prevents the risk of test question leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 This is a flow chart of a method for real-time perception and coordinated handling of network security situation of the present invention.
[0014] Figure 2 It is a schematic diagram of a method for real-time perception and coordinated handling of network security situation of the present invention.
[0015] Figure 3 This is another schematic diagram of a method for real-time perception and coordinated handling of network security situation of the present invention. DETAILED DESCRIPTION
[0016] In order to further understand the content of the present invention, the present invention is described in detail in conjunction with the accompanying drawings and embodiments. The present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It is understood that the specific embodiments described herein are only used to explain the relevant inventions, rather than to limit the invention. It is also necessary to explain that, for ease of description, only the parts related to the invention are shown in the accompanying drawings.
[0017] like Figure 1-3 In this embodiment, a method for real-time perception and coordinated handling of network security situation may specifically include:
[0018] S101. Obtain the test question download log in the campus network, extract the download time, user identity, course information and download amount from the download log, discretize the extracted data, and form a scattered batch initial behavior data set.
[0019] The test resource number, download timestamp and user identifier in the test resource server log are obtained, and the test download record table is obtained through the resource download record mark; the user authority level and the department to which the user belongs are read from the identity authentication database according to the user identifier in the test download record table, and the user identity feature vector is established to obtain a user portrait data set; the download behavior under each user identifier is time-sorted according to the download timestamp in the test download record table, and the time interval between adjacent downloads is calculated to obtain a user behavior time series data set; the user portrait data set and test question attributes are used to construct a user-test question association matrix, the user behavior time series data set is discretized, and a normalized user behavior feature data set is obtained through a data standardization method.
[0020] Specifically, the campus network data collection center is used to batch parse the logs of the question resource server, extract the original data items such as the question resource number, download timestamp, user identifier, and number of downloaded bytes from the log data, and generate the question download record table through the resource download record mark. For the user identifier in the question download record table, the user attribute data such as user authority level, department, and course information are read from the identity authentication database to establish the user identity feature vector and generate the user portrait data set. According to the download timestamp in the question download record table, the download behavior under each user identifier is sorted by time, the adjacent download time interval is calculated, and the download frequency of each user in different time periods is counted to generate the user behavior time series data set. For the question resource number in the question download record table, the resource attributes such as the question difficulty level and knowledge point classification are obtained from the course resource library, and the user-question association matrix is constructed in combination with the user portrait data set. The user behavior time series data set is segmented according to the download time interval, and the equal frequency binning method is used to convert the time interval into a discrete interval identifier to generate a discretized behavior sequence. Based on the user-question association matrix, the download proportion of each user for different course questions is calculated, and the user behavior feature data set is generated in combination with the discretized behavior sequence. The data standardization method is used to normalize the continuous features in the user behavior feature data set, and the categorical features are converted to one-hot encoding to output a standardized batch data set. In the campus network environment, the test download log contains multi-dimensional information. The complete download record can be obtained through log analysis. For example, a teacher downloaded the advanced mathematics final test at 10 am on March 15, 2024. The download process took 30 seconds and the number of downloaded bytes was 2048KB. These raw data were structured and stored in the test download record table. Each user identifier corresponds to rich identity information. Taking the college of science and engineering as an example, Teacher A has the authority level of proposition teacher, belongs to the Department of Computer Science, and is responsible for two core courses, discrete mathematics and data structure. These user attribute data constitute the basic dimension of user portrait. The download behavior of users often shows time regularity. Through analysis, it is found that the download frequency of Teacher B in the three time periods of the beginning, middle and end of the semester is 25 times, 38 times and 52 times respectively. The download interval is shortened from 48 hours in normal times to 6 hours in the exam week. This time series feature reflects the periodicity of teaching activities. The test resources themselves also contain rich attribute information. For example, the difficulty coefficient of the eigenvalue calculation questions in the linear algebra test bank is 0.8, and the knowledge points belong to the matrix theory branch. When teacher C downloads such test questions multiple times within a week, it means that the teacher has a strong correlation with the linear algebra course. When the time interval is discretized, the equal frequency binning method is used to divide 0-12 hours into frequent download intervals, 12-36 hours into regular download intervals, and more than 36 hours into low-frequency download intervals, thereby depicting the download behavior patterns of teachers in different periods.In the user behavior analysis, the probability statistics course taught by teacher Ding accounted for 85% of the total downloads, and 93% of the download behaviors occurred in the frequent download interval, which shows that the teacher invested a lot of energy in the question setting and exam preparation stage. After data standardization, the characteristics of each dimension are mapped to a unified numerical interval, which is convenient for subsequent data analysis. The correlation analysis of multi-dimensional data reveals the behavioral patterns of teachers in teaching activities such as lesson preparation and question setting. It also reflects the question setting characteristics and teaching cycles of different courses. For example, there are significant differences between the question setting rules of basic engineering courses and liberal arts professional courses, which provides data support for teaching management and resource allocation. In practical applications, by analyzing the download data of 50 teachers in a certain college in one semester, it is found that the average number of downloads of professional core course questions is 2.3 times that of general elective courses. This difference reflects the impact of the importance of courses on question setting investment.
[0021] S102. Identify download scenarios based on the initial behavior data set. Download scenarios include compliant scenarios and non-compliant scenarios. Compliant scenarios include accessing related course groups across courses during teaching seminars and review stages. Non-compliant scenarios include sudden download peaks and exam-sensitive periods, repeatedly switching between question banks of different courses, and analyzing download entrances, access sources, and access times. Generate a scenario classification data set based on the relevant data of download scenarios in different time periods.
[0022] A data miner is used to parse the download source network address, port number and access path identifier from the original download sequence to obtain a user access feature table; a time series analysis of user behavior is performed based on the user access feature table to obtain a course resource access path transfer probability matrix; download records for each time period are extracted based on the course resource access path transfer probability matrix, and a time period feature vector including the total time period downloads, download frequency, and maximum downloads per unit time is calculated; the time period feature vector is matched with the teaching activity time benchmark, and if the feature vector index value exceeds the preset threshold range, it is determined to be the corresponding scene type and a scene classification data set is generated.
[0023] Specifically, a data miner is used to read the initial behavior data set to obtain the user's original download sequence, and the download source network address, source port number, and access path identifier are parsed from the sequence to establish a user access feature table. The user behavior time series sequence is constructed based on the user access feature table, and the course knowledge graph association table is obtained from the course resource library. The number of course resource access switches per unit time is counted, and the course resource access path transfer probability matrix is calculated. For the course resource access path transfer probability matrix, the download records of each time period of the day are extracted, and the three indicator values of the total download amount, download frequency, and maximum download amount per unit time are calculated to generate the time period feature vector. The semester teaching calendar information is read from the teaching activity database, and the teaching seminar cycle, review and preparation cycle, and examination cycle are time-calibrated to establish the teaching activity time benchmark data. The download peak interval is identified based on the time period feature vector. If the total download amount exceeds the range of plus or minus two standard deviations of the interval mean, it is determined to be an abnormal download peak scenario. The sensitive time period interval is divided based on the teaching activity time benchmark data, and the access time in the user access feature table is interval matched to determine whether it belongs to the sensitive time period scenario. The course resource access path transfer probability matrix is used to calculate the degree of course switching. If the probability of switching between courses exceeds the set threshold, it is determined to be a frequent cross-course switching scenario. Feature extraction is performed on the identified various scenario data to generate a scenario classification data set containing scenario type, time feature, access feature, and course feature, so as to achieve structured storage of scenario data. In the campus network environment, users' test resource access behavior will leave rich digital footprints, such as source network address 202.118.1.88, port number 8080, access path / exambank / math / final and other feature information. These data form the basis for analyzing user behavior patterns. By observing the conversion rules of course resource access paths, it is found that there is a close connection between the knowledge points of advanced mathematics and linear algebra courses. When teachers access the matrix operation related test questions in Chapter 5 of advanced mathematics during lesson preparation, there is a 75% probability that they will continue to access similar knowledge point test questions in the linear algebra course. This access path transfer feature reflects the inherent connection between courses. In a typical teaching day, the access to test resources shows obvious time distribution characteristics. The total download volume from 9:00 to 11:00 in the morning reaches 350 times, which is 2.8 times the average value of the whole day, and the download frequency reaches 12 times per minute. This time period characteristic data provides an important basis for identifying download peaks. Teaching activities have a significant periodic pattern. Taking the spring semester as an example, the 1st to 16th teaching weeks are the regular teaching stage, the 17th to 18th weeks are the review and preparation stage, and the 19th to 20th weeks are the exam weeks. The test access behavior during the exam week needs special attention. In the download peak determination, the download volume from 10:00 to 11:00 in the morning of a certain teaching day reached 420 times, which exceeded the two standard deviations of the historical mean of 200 times in this period. The system automatically marked this period as an abnormal download peak scenario.Combined with the teaching weekly calendar data, it was found that the abnormal download peak occurred two days before the final exam week, which has a high risk characteristic. The continuity of course resource access is also an important basis for judgment. When it is observed that the user accessed the question bank of three courses, namely advanced mathematics, linear algebra, and probability statistics, in 5 minutes, and the access time of each course was less than 1 minute, this fast switching behavior pattern obviously deviated from the normal teaching and discussion scene. For different types of scene features, the system extracts multidimensional data including time dimension, access dimension, and course dimension. For example, the feature vector of an abnormal scene contains key information such as the access time is the morning of the second day of the exam week, the download peak is 30 times per unit time, the course switching frequency is 3 courses every 5 minutes, and the source is the non-teacher office area of the campus network. These structured scene data provide a data basis for subsequent behavior analysis and early warning.
[0024] S103. A clustering algorithm is used to analyze the download behavior of compliant scenarios in the scenario classification data set. By extracting the behavioral characteristics of students accessing cross-course related course groups during the teaching discussion and review stages, a compliant behavior characteristic model that describes the normal download frequency and reasonable user distribution is obtained.
[0025] According to the scenario classification data set, initial access sequence data with user identifiers and access timestamps are obtained, and the initial access sequence data includes course number information; the initial access sequence data is processed by a sliding time window method to obtain a user access behavior time series feature table with statistical values of the number of visited courses, and the user access behavior time series feature table includes adjacent access time differences; course group marking is performed on the user access behavior time series feature table, and the course group marking is determined by extracting the course group division table obtained by extracting the correlation relationship between course knowledge points in the teaching resource library; the frequency distribution of course group visits by users in the discussion stage and the review stage is calculated according to the user access behavior time series feature table, and the user access pattern clustering center is obtained by a density clustering method, and the user access pattern clustering center is used to construct a user behavior feature vector, and a compliance behavior feature model is established based on the user behavior feature vector.
[0026] Specifically, a data filter is used to read compliance scenario records from the scenario classification dataset, extract three basic data items: user identifier, access timestamp, and course number, and generate an initial access sequence dataset. The difference between adjacent access times is calculated based on the initial access sequence dataset, and the number of user access courses in the window is counted using the sliding time window method to generate a user access behavior time series feature table. The course knowledge structure map is obtained from the teaching resource library, the relationship between knowledge points between courses is extracted, a course group division table is constructed, and the groups to which the courses belong in the user access behavior time series feature table are marked. For the marked access behavior time series feature table, the frequency distribution of users visiting different course groups in the discussion stage and review stage is calculated, and the density clustering method is used to obtain the user access pattern cluster center. Based on the user access pattern cluster center, a user behavior feature vector is constructed, which includes three feature dimensions: total daily access time, average access interval, and course switching frequency. The user behavior feature vector is tested for normal distribution, the mean and standard deviation of the features of each dimension are calculated, and a feature distribution interval boundary value table is generated. According to the feature distribution interval boundary value table, the user behavior feature vector is classified. If the three feature dimensions are within the range of plus or minus two standard deviations of the mean, it is determined to be a compliance behavior feature. The association rule mining algorithm is used to extract the user access course group combination pattern from the compliance behavior feature data, and a compliance behavior feature model containing time series features, user features, and course features is constructed. In the process of analyzing compliance scenarios, it is first necessary to extract basic features from the original data. For example, user identifier U2024001 accessed the exercises of Chapter 4 of Advanced Mathematics at 9 am on March 15, and accessed the exercises of Chapter 3 of Linear Algebra at 10:30. These records constitute the initial access sequence. By calculating the access interval, it is found that the time difference between the adjacent visits of the user in the morning is 90 minutes. Using a 30-minute sliding window statistics, it is found that in each window, an average of 2 to 3 different courses of test resources are accessed. This access pattern reflects the normal learning behavior of users during the teaching and seminar stage. From the perspective of the course knowledge structure, there is a clear correlation between the three knowledge points of matrices and determinants in advanced mathematics, linear equations in linear algebra, and random matrices in probability statistics. They naturally form a course group, and users present a coherent learning path when accessing these related courses. In the discussion stage and the review stage, the user access pattern presents different characteristics. For example, the average daily access time of a certain user group in the discussion stage is 180 minutes, with a standard deviation of 30 minutes; the average access interval is 45 minutes, with a standard deviation of 10 minutes; the course switching frequency is 4 times per hour, with a standard deviation of 1 time. In the review stage, these indicator values will increase accordingly but still remain within a stable range.After clustering analysis of a large amount of user behavior data, it was found that the behavioral feature vectors of compliant users are usually distributed in a relatively concentrated range, such as a single-day visit duration between 120 and 240 minutes, a visit interval between 30 and 60 minutes, and a course switching frequency between 3 and 5 times per hour. These numerical ranges constitute the benchmark for determining compliant behavior. When extracting course access combination patterns, it was found that the association rules in science and engineering course groups have significant characteristics. For example, after a user accesses calculus questions, there is an 80% probability that he will continue to access related questions in advanced algebra. This strong association reflects the inherent connection of the course content. These access rules are refined as an important part of the compliant behavior feature model. From the perspective of time series, compliant users show similar course group access patterns in both the discussion and review stages. For example, within a teaching cycle, users will systematically access relevant test questions in the same course group within a fixed time period. This stable access pattern is highly consistent with the rules of teaching activities. Through comprehensive analysis of these multi-dimensional characteristics, the constructed compliance behavior characteristic model accurately describes the test question access behavior in normal teaching activities, covering the three key dimensions of time characteristics, user characteristics and course characteristics.
[0027] S104. Obtain anonymous download accounts for non-compliant scenarios, and use anomaly detection algorithms to identify behaviors that deviate from the compliant behavior feature model. If the download volume increases suddenly during the sensitive exam period, the user identity is single and concentrated, and the user repeatedly switches between question banks of different courses, the download behavior is judged to be abnormal download, and the behavioral features of the abnormal download behavior are extracted to generate an abnormal behavior feature model.
[0028] Obtain non-compliant scenario data with a download account identifier and a login time period, wherein the non-compliant scenario data is generated when an anonymous account downloads; extract the access source address and account creation time according to the non-compliant scenario data, and generate an account basic data table, wherein the account basic data table includes an account identifier and its basic feature items; perform sensitive time period interval matching on the account basic data table, wherein the sensitive time period interval is determined by the examination cycle schedule in the academic affairs management database; use an isolation forest algorithm to perform anomaly detection on the sensitive time period access records, and obtain an anomaly indicator data table, wherein the anomaly indicator data table includes the total download volume and access duration of a single account; extract the course access sequence feature value according to the anomaly indicator data table, calculate the state transition probability matrix of the course access sequence through a Markov chain, extract the course access state transition law, and construct a user access behavior sequence model; calculate the behavior deviation of each account based on the user access behavior sequence model, and construct an abnormal behavior feature model in combination with the anomaly indicator data table.
[0029] Specifically, the data extractor is used to obtain anonymous download account records from non-compliant scenario data, and the user information in the identity authentication database is compared to extract the four basic feature items of download account identifier, login time period, access source address, and account creation time to generate an account basic data table. The exam cycle schedule is obtained from the academic affairs management database, and the range from 7 days before the exam week to the end of the exam is extracted as the sensitive period range. The login time period in the account basic data table is interval matched to generate a sensitive period access record table. For the sensitive period access record table, the total daily download volume, single-day access duration, and number of access source addresses of a single account are counted. The isolated forest algorithm is used to detect data anomalies to generate an abnormal indicator data table. According to the abnormal indicator data table, the course access sequence of the marked account is extracted, and the three feature values of course switching interval, repeated access number, and course knowledge point coverage are counted to generate a course access feature table. The Markov chain is applied to the course access feature table to calculate the course transition probability matrix, extract the course access state transition law, and construct a user access behavior sequence model. Based on the user access behavior sequence model, the behavior deviation of each account is calculated, and combined with the abnormal indicator data, an abnormal behavior feature vector containing time features, access features, and course features is generated. Cluster analysis method is used to perform clustering operation on abnormal behavior feature vectors, calculate inter-cluster distance and intra-cluster distance, and identify abnormal behavior pattern groups. Common feature rules are extracted according to abnormal behavior pattern groups, and abnormal behavior feature models including abnormal judgment threshold, behavior feature description, and pattern recognition rules are constructed. In non-compliant scenarios, anonymous download accounts show unique behavioral characteristics. For example, account A12345 began to download a large number of test resources within 24 hours after creation, and its access source address changed more than 5 times within 1 hour, from 202.118.1.88 to 202.118.2.156 and then to 202.118.3.224. This frequently changing access feature obviously deviates from normal user behavior. In terms of examination cycle determination, taking the spring semester as an example, when it is detected that the 7 days before the start of the final exam week, that is, June 8 to June 28, is marked as a sensitive period, the account activities during this period will be monitored. Statistics show that account B67890 downloaded 280 times on June 10, eight times more than during normal teaching days, and 93% of downloads were concentrated between 11 p.m. and 3 a.m. The Isolation Forest Algorithm found that normal users usually download no more than 50 times a day, and their daily visits last between 120 and 240 minutes, while abnormal account C34567 downloaded 320 times and visited for only 75 minutes. This high-frequency, short-term visit pattern is significantly different from normal behavior.In the course access behavior analysis, it was found that account D89012 continuously switched to access the question banks of three courses, namely, advanced mathematics, linear algebra, and probability statistics, within 5 minutes. The stay time for each course was less than 40 seconds, and the knowledge point coverage rate was only 15%. This superficial access feature is obviously inconsistent with the teaching and discussion scenario. When using Markov chain to analyze the course transfer probability, it was found that after normal users have visited a course, there is an 80% probability that they will continue to study the relevant knowledge points in depth, while the course transfer of abnormal account E23456 is random, and the transfer probability between courses is close to uniform distribution. Through cluster analysis, it was found that the abnormal behavior feature vector formed obvious clusters in the feature space, with the inter-cluster distance reaching 0.85, while the intra-cluster distance was only 0.12, indicating that the abnormal behavior patterns have a high similarity. Among them, the time feature is active during sensitive periods, the access feature is high frequency and short time, and the course feature is random switching. In the abnormal behavior feature model, multiple key thresholds are set, such as more than 200 downloads per day, less than 60 seconds of average course stay time, less than 20% of course knowledge point coverage, etc. These indicators together constitute the criteria for determining abnormal behavior. Based on these characteristic rules, the identified abnormal account groups show a significant clustering effect, and show obvious regularity in both time and space dimensions. In actual applications, through the analysis of data from a school's final exam week in the spring semester of 2023, it was found that more than 85% of abnormal download behaviors conform to the above characteristic patterns. This high degree of pattern similarity provides strong support for the early identification of abnormal behavior.
[0030] Obtain the timestamp sequence of abnormal download behavior, calculate the statistical distribution of time intervals, analyze the temporal clustering of download behavior, build a directed graph model of course access based on course access records, extract the jump frequency and access path between courses, and combine IP addresses, device identifiers, and login credentials to identify co-occurrence relationships and reuse patterns between accounts.
[0031] A download timestamp sequence is obtained according to an abnormal database, and the interval distribution of the download timestamp sequence is calculated by a kernel density estimation method to obtain a time series aggregation data table; based on the time series aggregation data table, a course access sequence within a high-frequency download period is screened out, and a course node relationship matrix is constructed through the course access sequence to obtain a course jump network diagram; for abnormal paths detected in the course jump network diagram, the network address segment, hardware device identification code, and login token identification in the account login data within the period corresponding to the abnormal path are parsed to generate an account login feature sequence; the account login feature sequence is segmented by a sliding time window method, and the overlap value of the feature sequence within the time window is calculated to obtain an account feature similarity matrix; an account association diagram is constructed according to the account feature similarity matrix, and the account login time overlap, access feature similarity, and device feature co-occurrence are analyzed based on the account association diagram.
[0032] Specifically, the account timestamp sequence is obtained from the abnormal download database, and the kernel density estimation method is used to calculate the download time interval distribution function. The time series is segmented at the hourly level, and the download frequency and interval variance in the unit time period are counted to generate a time series aggregation data table. According to the time series aggregation data table, the high-frequency download period records are screened, the course access sequence in the period is extracted, the course node relationship matrix is constructed, the access transfer probability between courses is calculated, and the course jump network diagram is generated. For the abnormal path in the course jump network diagram, the account login data in the corresponding period is extracted, and the three features of network address segment, hardware device identification code, and login token identification are analyzed to generate the account login feature sequence. The sliding window method is used to segment the account login feature sequence in time, calculate the overlap of the feature sequence in the time window, and generate the account feature similarity matrix. According to the account feature similarity matrix, an account association graph is constructed, and the feature similarity threshold is set to extract the high-similarity account group to form an account aggregation relationship table. The community detection algorithm is applied to the account aggregation relationship table, and the account community division results are generated based on the three dimensions of account login time overlap, access feature similarity, and device feature co-occurrence. Based on the results of the account community division, the activity patterns of the accounts in the group are counted, the login sequence correlation, device reuse frequency, and access mode coordination between accounts are calculated, and the account reuse feature vector is constructed. The hierarchical clustering method is used to cluster the account reuse feature vector, extract the typical reuse mode features, and establish an account reuse relationship model containing timing features, correlation features, and reuse features. In the analysis of abnormal download behavior, the timestamp sequence reveals a unique access pattern. For example, the download time interval of a group of accounts between 2 am and 4 am is highly regular, with each download interval of 15 seconds and a variance of only 2 seconds. This mechanical access rhythm is obviously different from normal user behavior. Through in-depth analysis of high-frequency download periods, it is found that in the late night period of the week before the exam week, multiple accounts show similar course access paths, from advanced mathematics to linear algebra to probability statistics, and the transfer probability between courses is as high as 0.95. This fixed access sequence indicates that there may be batch download behavior. In terms of account login characteristics, it was found that a group of suspicious accounts shared similar device characteristics, such as the last three digits of the device identification code differed, and the network address segments all belonged to the same Class C subnet. This highly similar login feature suggests that the accounts may have originated from the same batch registration process. Using a 30-minute sliding time window, it was found that the login time series overlap of account A and account B reached 85%, and their course access sequence similarity reached 0.92, and the device feature matching degree was 0.88. This high multi-dimensional similarity strongly suggests that the two accounts may be controlled by the same operator. In the account community division, a close group of 12 accounts was identified. The active time windows of these accounts were staggered. When the access frequency of one account decreased, another account immediately began to access at a high frequency, forming a relay access pattern.The account reuse pattern also shows significant characteristics. For example, in group G1, the average life cycle of an account is 48 hours. After a single account reaches the download limit, it is immediately replaced by a new account, and the device feature similarity of the new and old accounts reaches 0.96. This regular account replacement pattern indicates the existence of an organized account management strategy. Through hierarchical cluster analysis, all suspicious accounts are divided into three main categories: short-term high-frequency type, periodic rotation type, and decentralized collaborative type. Among them, the daily download volume of short-term high-frequency type accounts exceeds 200 times, and the active time is concentrated within 48 hours; the periodic rotation type accounts maintain a relatively stable daily download volume of 50 times, but will regularly change the access period; the decentralized collaborative type accounts evade monitoring by having multiple accounts online at the same time and staggered access. In an actual case, a university found that the download behavior of a group of accounts in the final week was highly correlated. They used 5 IP addresses from the same network segment, shared 2 sets of device identification features, and completed more than 8,000 test downloads in 4 days. This obvious collaborative behavior feature is highly consistent with the features predicted by the above model.
[0033] S105. The pre-built sandbox environment is monitored in real time based on the abnormal behavior feature model. If it is detected that the anonymous download account has a sudden increase in download volume and frequently cross-compares cross-course test questions during the sensitive examination period, it is determined that the sandbox boundary breach warning has been triggered and a warning signal is generated.
[0034] Obtain the account behavior data stream in the sandbox environment, extract the access timestamp, the number of downloaded resources and the resource type number according to the data stream, and obtain the real-time account behavior record table; mark the sensitive time interval according to the real-time account behavior record table and the examination cycle arrangement data, and filter the behavior record table by time period division tool to obtain the sensitive time period monitoring data table; construct a monitoring indicator system including hourly download growth rate, test question access frequency and course repeat access rate for the sensitive time period monitoring data table, and generate a monitoring indicator threshold table using an abnormal behavior feature model; calculate the real-time value of the monitoring indicator by comparing with the monitoring indicator threshold table, and perform weighted sum operation on the indicator deviation by feature fusion calculation method. If the behavior score exceeds the warning threshold, a boundary breach event is triggered to generate a warning data packet.
[0035] Specifically, a data collector is used to read the real-time behavior data stream of anonymous download accounts from the sandbox environment, extract the three basic data items of hourly access timestamp, number of downloaded resources, and resource type number, and generate an account real-time behavior record table. The examination cycle arrangement data is obtained from the examination management database, and the period division tool is used to mark the period from 7 days before the start of the examination week to the end of the examination as a sensitive time interval. The account real-time behavior record table is filtered to generate a sensitive period monitoring data table. A real-time monitoring indicator system is constructed based on the abnormal behavior feature model, including three indicators: hourly download growth rate, test question access frequency, and course repeated access rate, and a monitoring indicator threshold table is generated. The real-time value of the monitoring indicator is calculated for the sensitive period monitoring data table, and a multi-dimensional threshold comparison is performed against the monitoring indicator threshold table to generate indicator deviation data. The feature fusion calculation method is used to perform weighted summation on the indicator deviation data, and the comprehensive score of abnormal behavior is calculated in combination with the feature weight matrix to generate a behavior score sequence. The score mean and standard deviation are calculated according to the time distribution characteristics of the behavior score sequence, and the score mean plus two times the standard deviation is set as the breakthrough warning benchmark value to generate a dynamic warning threshold. The real-time behavior score is compared with the dynamic warning threshold. If the behavior score exceeds the warning threshold, a boundary breach event is triggered and a warning data packet containing the account ID, breach time, and breach degree is generated. The warning level is calculated based on the warning data packet, and the breach degree is graded using a rating quantizer to generate a graded warning signal. In the sandbox environment, the behavioral characteristics of abnormal accounts often present unique data patterns. For example, the download volume of account M2024001 from 12 to 108 from 10:00 to 11:00 on June 15, and the resource type has expanded from a single advanced mathematics to multiple courses such as linear algebra and probability theory. This sudden behavioral change triggered a real-time monitoring warning. In terms of the division of the exam cycle, taking the spring semester final exam as an example, the monitoring system marks June 15 to June 28 as a sensitive time interval, and the account behavior during this period will be more strictly monitored. In this interval, the download behavior of the account presents obvious time series characteristics, such as 3 to 5 a.m. is the peak download period. This unconventional time distribution causes significant fluctuations in monitoring indicators. The monitoring indicator system describes account behavior through multi-dimensional features. The hourly download growth rate reflects the suddenness of account behavior. The growth rate of normal users is usually within 50%, while that of abnormal accounts can reach 800%. The frequency of test questions describes the access rhythm of the account. The access interval of the normal review process is more than 3 minutes, while the interval of batch download behavior is usually within 10 seconds. The course revisit rate reveals the randomness of the access path. In the calculation of indicator deviation, a group of accounts showed highly similar behavioral characteristics: the deviation of the download growth rate reached 3.6, the deviation of the test question access frequency was 4.2, and the deviation of the course revisit rate was 2.8. Through feature fusion calculation, the three indicators were assigned weights of 0.4, 0.35, and 0.25 respectively, and the comprehensive score of abnormal behavior reached 3.8.Based on historical data statistics, the mean of normal account behavior scores is 1.2, and the standard deviation is 0.4. Based on this, the warning baseline value is set to 2.0. When the real-time behavior score exceeds this threshold, the system determines that a boundary breach event has occurred. In actual cases, the scores of a batch of accounts jumped from 1.1 to 3.5 in a short period of time, and at the same time showed obvious group characteristics. This mutation triggered a high-level warning signal. The warning classification adopts a four-level system. Scores between 2.0 and 2.5 are level 4 warnings, 2.5 to 3.0 are level 3 warnings, 3.0 to 3.5 are level 2 warnings, and 3.5 and above are level 1 warnings. For example, in a certain monitoring, it was found that 5 related accounts triggered level 2 warnings at the same time, and their access behaviors had obvious temporal coordination. This group of abnormal behaviors caused the system to generate a higher level of warning signals. In a typical warning case, the system captured abnormal behavior of a group of accounts in the three days before the exam week. The average download volume was seven times the usual amount, the access interval was shortened from minutes to seconds, and there was frequent switching between multiple course resource repositories, which eventually triggered a level one warning. The warning data packet recorded in detail the characteristic evolution of the entire abnormal process.
[0036] In the test resource access platform of the campus network, resource access rules based on user identity and course attributes are set at the permission control layer, and the test resources of different courses are logically isolated. A dynamic threshold control module is deployed at the resource call layer to limit the number and frequency of test downloads in real time. Data collection probes are implanted in the behavior monitoring layer to record the timing characteristics and access patterns of account operations, so as to build a three-level isolated test resource access sandbox environment.
[0037] A user authority table is generated according to a user identity authentication database, and the user identity and access rules for course resources are obtained through a permission mapper, wherein the access rules are obtained by subject classification of course test question resources by a resource grouper; a resource isolator is deployed using the access rules, and an independent access domain is established for course test question resources, wherein the independent access domain is formed by partitioning and storing the test question resources by resource identification coding; an access frequency benchmark value is calculated according to historical access statistical data in the independent access domain, and resource call restriction rules are set according to the access frequency benchmark value, wherein the resource call restriction rules include an upper limit on the amount of downloads per unit time and a minimum access interval; a data acquisition probe is used to obtain user access data flows in the independent access domain, and behavioral data including access timestamps and resource numbers are recorded, and the behavioral data is processed by a feature extractor and stored in a behavioral feature database.
[0038] Specifically, a user permission table is generated based on the user identity authentication database, and the course test resources are classified by subject using a resource grouper. The access rules for user identity and course resources are established through a permission mapper to generate a course resource access rule library. A resource isolator is deployed based on the course resource access rule library, and independent access domains are established for different course test resources. The test resources are partitioned and stored using resource identification coding to build a resource isolation access structure. The access frequency benchmark value is calculated based on historical access statistics, and resource call restriction rules including the upper limit of downloads per unit time, the minimum access interval, and the number of consecutive accesses are set to generate a resource call control table. A data acquisition probe is used to obtain the user access data flow, record the behavioral data including the access timestamp, resource number, and operation type, extract features from the collected data, and store them in the behavioral feature database. An access rule validator is deployed at the resource access entrance, and permission verification is performed based on the user identity, and access rights are determined by comparing with the course resource access rule library. A frequency controller is implanted in the resource call interface, and access requests are counted and counted based on the resource call control table, and access is blocked for requests that exceed the restriction rules. Data collectors are deployed at user behavior monitoring points to record user operation data in real time, perform feature matching based on the behavior feature database, and identify abnormal access patterns. A three-level protection link is built through rule validators, frequency controllers, and data collectors to achieve a sandbox environment with user identity isolation, resource call isolation, and behavior monitoring isolation. In the campus network environment, the access rule library implements resource access control through refined permission division. For example, teacher users are divided into permission groups according to teaching relationships. Mathematics teachers can only access mathematics test resources, and the specific access domains are independent of different courses such as calculus and linear algebra. The resource isolation structure adopts a multi-layer partition storage strategy to encode and divide test resources according to disciplines, courses, and chapters. For example, the mathematics resource code starts with MATH, where the calculus test is coded as MATH-CALC, and the first chapter test is coded as MATH-CALC-01. This hierarchical structure ensures the precise positioning of resource access. In terms of resource call control, specific restriction rules are set based on historical access data: the upper limit of the access frequency of ordinary users is 10 times per minute, the minimum access interval is 3 seconds, and the number of consecutive accesses does not exceed 50 times. These benchmark values are based on the access mode of normal teaching activities and match the actual usage scenarios. The data collection probe records detailed behavioral data every time the user accesses, including the timestamp of the access, the resource number requested, and the type of operation performed. For example, it records the download operation of user A accessing the MATH-CALC-01 resource at 10:30:25. These raw data form the basis for behavioral analysis. During the access rule verification process, the user identity is verified in multiple dimensions, such as verifying the user's department, teaching courses, and access permission level. When Teacher A from the Department of Mathematics accessed the physics test questions, the system automatically rejected the access request because it did not meet the course resource access rules.The frequency controller monitors the resource call situation in real time. When it is found that the user has initiated 20 download requests in succession within 5 seconds, which exceeds the minimum access interval and the access limit per unit time, the system immediately starts the access blocking mechanism. At the behavior monitoring level, the data collector identifies abnormal patterns by analyzing the user operation sequence. For example, if it is found that the user frequently switches between different course question resources in the late night period, and the access time interval for each resource is fixed at 15 seconds, this mechanized access pattern is marked as suspicious behavior. The three-level protection link forms a progressive protection through rule verification, frequency control, and behavior monitoring. Taking an abnormal access as an example, the rule verification layer first identifies the user access rights mismatch, and the frequency control layer finds the access frequency abnormality. Finally, the behavior monitoring layer captures the abnormal operation mode. The three layers of protection jointly build a strict security barrier. Through this multi-level protection mechanism, the access behavior of question resources is effectively regulated, and the safe use of teaching resources is guaranteed.
[0039] S106. Analyze the warning signals and the sandbox environment security logs. If the resource usage rate increases suddenly, the permissions change frequently, and the network traffic soars, it is determined that the sandbox boundary has been maliciously breached, and the breach feature analysis results are obtained.
[0040] Receive resource usage records, permission operation records, and network access records in the early warning signal library and the sandbox security log, and generate a security event data table from the resource usage records, permission operation records, and network access records; count the resource occupancy and permission modification frequency per unit time according to the security event data table, generate a resource occupancy situation table through the resource occupancy, and generate a permission change frequency table through the permission modification frequency; use the Gaussian mixture clustering method to identify abnormal intervals of network traffic data in the security event data table, and use the results of abnormal interval identification to generate a traffic mutation situation table; use a feature fusion device to perform data association on the resource occupancy situation table, the permission change frequency table, and the traffic mutation situation table to obtain a multi-dimensional abnormal feature matrix, and if the feature similarity score of the multi-dimensional abnormal feature matrix exceeds a breakthrough judgment threshold, generate a boundary breakthrough report.
[0041] Specifically, the log parser is used to read the early warning signal library and sandbox security log, extract three types of data items: resource usage records, permission operation records, and network access records, and generate a security event data table. According to the security event data table, the resource usage rate change trend is counted, and the growth rate of resource occupancy per unit time is calculated to generate a resource occupancy situation table. The permission change record is extracted from the security event data table, and the permission modification frequency per unit time is calculated by the time window counter to generate a permission change frequency table. Based on the security event data table, network traffic data is extracted, and the Gaussian mixture clustering method is used to identify traffic anomaly intervals to generate a traffic mutation situation table. The resource occupancy situation table, permission change frequency table, and traffic mutation situation table are associated with data through the feature fusion device to construct a multi-dimensional abnormal feature matrix. The collaborative filtering calculation method is used to analyze the feature correlation of the multi-dimensional abnormal feature matrix, calculate the strength of the collaborative relationship between features, and generate a feature correlation table. According to the feature correlation table, the breakthrough feature combination is extracted, compared with the known breakthrough mode in the breakthrough behavior feature library, and the feature similarity score is calculated. The breakthrough judgment threshold is set based on the feature similarity score, and the breakthrough quantifier is used to grade the abnormality degree, generating a boundary breakthrough report including breakthrough time, breakthrough characteristics, and breakthrough degree. In the security monitoring of the sandbox environment, the warning signal and security log record the key indicators of system operation. For example, an abnormal account triggered 15 warning signals within 10 minutes, and the security log showed that the resource access volume of the account surged from 20 times per minute to 180 times. This sudden change has attracted attention from security event data. In terms of resource usage monitoring, the resource occupancy rate of normal users usually shows a stable change, with an increase of less than 20%. In a breakthrough event, the server CPU occupancy rate climbed from 15% to 85% in 3 minutes, and the memory occupancy jumped from 40% to 95%. This drastic fluctuation in resource occupancy indicates that the system is suffering from abnormal access. The permission change behavior also shows unique time series characteristics. Through the 5-minute sliding time window statistics, it is found that the frequency of permission modification of ordinary users usually does not exceed 3 times. In the breakthrough event, the frequency of permission change of a group of accounts reached 45 times, and the permission change behavior of multiple accounts showed a high degree of time series correlation. The network traffic data showed a clear bimodal distribution through Gaussian mixture clustering. Normal traffic was concentrated at around 2MB per second, while abnormal traffic increased to 15MB per second. The traffic samples in the abnormal range accounted for more than 15% of the total samples. This significant traffic mutation suggests batch download behavior of resources. Multi-dimensional feature fusion reveals the synergy of breakthrough behaviors. The three indicators of resource occupancy rate, permission change frequency and traffic change rate show strong correlation, with a correlation coefficient of 0.85, indicating that these abnormal behaviors are likely to originate from the same breakthrough event. Feature correlation analysis shows that permission changes often precede resource occupancy and traffic surges, with an average lead time of 90 seconds.In the feature similarity matching, the feature vector of a certain breakthrough event has a similarity of up to 0.92 with the "bulk resource theft" mode in the feature library, of which the resource occupation mode similarity is 0.94, the permission operation mode similarity is 0.89, and the traffic feature similarity is 0.93. This high degree of feature matching strongly confirms the occurrence of the breakthrough behavior. The boundary breakthrough report records the evolution of the entire incident: the breakthrough began at 2:15 a.m., first manifested as frequent attempts to escalate permissions, and then triggered a sharp increase in resource usage at 2:18, and triggered the traffic alarm threshold at 2:20. The entire breakthrough process lasted about 8 minutes, during which more than 200 abnormal behavior records were generated. The degree of breakthrough was quantified as 9.2 points out of 10 points. The multi-dimensional breakthrough feature analysis provides an important basis for subsequent protective measures.
[0042] S107. Dynamically adjust the sandbox security policy based on the breakthrough feature analysis results, including limiting the download permissions of abnormal anonymous accounts, isolating the surge in malicious traffic, and optimizing the allocation of suddenly increased resources, and apply the dynamically adjusted sandbox security policy to the sandbox.
[0043] A breakthrough quantizer is used to process the abnormal account identification list, the malicious traffic characteristic value and the resource occupancy mutation point data to obtain security policy adjustment data including a breakthrough level parameter, a breakthrough range parameter and a breakthrough degree parameter; a permission adjustment parameter value is calculated according to the security policy adjustment data, a download count limit value, an access interval limit value and an operation permission limit value are generated through a permission downgrade processor, and permission management and control are implemented on the accounts in the abnormal account identification list through the permission downgrade processor; a resource monitor is used to read the resource occupancy mutation point data to calculate the CPU usage upper limit value, the memory occupancy upper limit value and the storage space upper limit value, and a sandbox security policy package including the permission limit value, the traffic limit value and the resource upper limit value is generated through a policy synthesizer.
[0044] Specifically, three key indicators, namely, abnormal account identification list, malicious traffic characteristic value, and resource occupancy mutation point, are extracted from the breakthrough feature analysis results. The breakthrough quantifier is used to generate security policy adjustment suggestions including breakthrough level, breakthrough range, and breakthrough degree. The permission adjustment parameters are calculated based on the security policy adjustment suggestions. The permission downgrade processor is used to generate download limit value, access interval limit value, and operation permission limit value, and an account permission control scheme is constructed. Abnormal accounts are marked according to the account permission control scheme, and access requests of marked accounts are diverted. The maximum traffic value per unit time is limited by the traffic controller to generate traffic control rules. Bandwidth allocation thresholds are set based on traffic control rules, and the source of abnormal traffic is identified by the traffic analyzer. Traffic exceeding the threshold is redirected and isolated to generate a traffic isolation strategy. The resource monitor is used to read the resource occupancy mutation point data, and the three resource restriction parameters of CPU usage upper limit, memory occupancy upper limit, and storage space upper limit are calculated to generate a resource restriction scheme. Resource allocation rules are constructed based on the resource restriction scheme, and the quotas of computing resources, storage resources, and network resources are set by the resource scheduler to generate a resource quota table. The policy synthesizer is used to integrate the account permission control scheme, traffic isolation strategy, and resource quota table to generate a sandbox security policy package containing all control parameters. The sandbox security policy package is written into the sandbox configuration library through the policy deployer, and permission control is implemented for abnormal accounts, malicious traffic is isolated, and sudden resource increases are restricted to complete the dynamic adjustment of security policies. In the breakthrough feature analysis, different levels of breakthrough behaviors correspond to different policy adjustment measures. For example, the breakthrough level of an account is 8.5 points, and the breakthrough range involves 3 course resource libraries. The breakthrough degree is 4 times the access limit. This serious cross-border behavior triggers the highest level of policy adjustment. In terms of permission control, differentiated restrictions are implemented according to the breakthrough degree of the account, reducing the upper limit of downloads from 100 times per hour to 10 times, extending the access interval from 3 seconds to 30 seconds, and downgrading the operation permission from full access to read-only access. This refined permission adjustment ensures effective control of abnormal accounts. Traffic control uses a multi-level restriction strategy. When it detects that the download traffic of account A surges from 2MB / s to 20MB / s within 5 minutes, the traffic controller immediately starts bandwidth restriction, limiting the maximum transmission rate to less than 5MB / s, and redirects the traffic exceeding the threshold to low-priority resource channels. Resource usage control prevents resource abuse by setting hard limits. When a group of accounts is monitored to cause the server CPU usage to exceed 90%, the CPU usage limit of a single account is immediately set to 10%, the memory usage limit is set to 512MB, and the storage access rate is limited to 50IOPS. These restriction parameters constitute the basic resource quota.In the process of strategy integration, the control measures of various dimensions form a coordinated protection system. For example, when account B triggers the permission restriction, its related traffic is automatically marked as suspicious traffic, and the resource quota is lowered at the same time. The restrictions of the three dimensions work together to form a tight protection network. The strategy deployment adopts a real-time effectiveness mechanism. Once it is detected that account C downloads test questions in batches during the late night period, the system completes the permission adjustment within 200 milliseconds, implements traffic isolation within 500 milliseconds, and completes resource reallocation within 1 second. The entire response process reflects the real-time nature of the strategy adjustment. In actual applications, a university discovered a group of suspicious accounts during the final exam week and successfully prevented breakthrough behaviors by dynamically adjusting policies. First, the access frequency limit was implemented for 5 abnormal accounts, reducing the maximum access rate to 1 / 5 of the normal value; secondly, the 435MB / s abnormal traffic generated by these accounts was isolated, and the impact on normal business was reduced by traffic redirection; finally, the resource allocation strategy was adjusted to reduce the resource usage priority of these accounts to the lowest, effectively ensuring the normal access of other users. Through this multi-dimensional dynamic policy adjustment, the sandbox environment achieves precise control of abnormal behaviors, which not only ensures the effective containment of breakthrough behaviors, but also maintains the smooth progress of normal teaching activities. The granularity of policy adjustment is accurate to a single account and specific resources, realizing the minimization of the impact of protective measures.
[0045] The above only lists some preferred embodiments of the present invention, but the present invention is not limited thereto, and many improvements and changes can be made. As long as the improvements and changes are made on the basis of the basic principles of the present invention, they should be regarded as falling within the protection scope of the present invention.
Claims
1. A method for real-time perception and coordinated handling of network security situation, characterized in that: The method comprises: Obtain the test question download logs from the campus network, extract the download time, user identity, course information and download volume from the download logs, discretize the extracted data, and form a scattered batch initial behavior data set; Identify download scenarios based on the initial behavior data set. Download scenarios include compliant scenarios and non-compliant scenarios. Compliant scenarios include accessing related course groups across courses during teaching seminars and review stages. Non-compliant scenarios include sudden download peaks and exam-sensitive periods, repeatedly switching between question banks of different courses, and analyzing download entrances, access sources, and access times. Generate a scenario classification data set based on the relevant data of download scenarios in different time periods. A clustering algorithm is used to analyze the download behavior of compliance scenarios in the scenario classification dataset. By extracting the behavioral characteristics of students accessing cross-course related course groups during the teaching discussion and review stages, a compliance behavior feature model that describes the normal download frequency and reasonable user distribution is obtained. Obtain anonymous download accounts for non-compliant scenarios, use anomaly detection algorithms to identify behaviors that deviate from the compliant behavior feature model, and if the download volume increases suddenly during the sensitive exam period, the user identity is single and concentrated, and the user repeatedly switches between question banks of different courses, the download behavior is judged to be abnormal download, and the behavioral features of the abnormal download behavior are extracted to generate an abnormal behavior feature model; The pre-built sandbox environment is monitored in real time based on the abnormal behavior feature model. If an anonymous download account is detected to have a sudden increase in downloads during the sensitive exam period, or to frequently cross-compare test questions across courses, it is determined that a sandbox boundary breach warning has been triggered, and a warning signal is generated; Analyze warning signals and sandbox environment security logs. If resource usage increases suddenly, permissions change frequently, or network traffic surges, it is determined that the sandbox boundary has been maliciously breached, and the breach feature analysis results are obtained. Dynamically adjust the sandbox security policy based on the breakthrough feature analysis results, including restricting the download permissions of abnormal anonymous accounts, isolating surging malicious traffic, and optimizing the allocation of suddenly increased resources. Apply the dynamically adjusted sandbox security policy to the sandbox.
2. The method according to claim 1, characterized in that The method of obtaining the test question download log in the campus network, extracting the download time, user identity, course information and download amount from the download log, and discretizing the extracted data to form a scattered batch initial behavior data set includes: Obtain the question resource number, download timestamp and user identifier in the question resource server log, and obtain the question download record table through the resource download record mark; Read the user authority level and the department to which the user belongs from the identity authentication database according to the user identifier in the test question download record table, establish the user identity feature vector and obtain the user portrait data set; According to the download timestamp in the test question download record table, the download behavior under each user identifier is sorted in time, and the time interval between adjacent downloads is calculated to obtain a user behavior time series data set; The user portrait data set and test question attributes are used to construct a user-question association matrix, the user behavior time series data set is discretized, and a normalized user behavior feature data set is obtained through a data standardization method.
3. The method according to claim 1, characterized in that The download scenarios are identified based on the initial behavior data set. The download scenarios include compliant scenarios and non-compliant scenarios. The compliant scenarios include accessing related course groups across courses during the teaching seminar and review phase. Non-compliant scenarios include sudden download peaks and exam sensitive periods, repeatedly switching between question banks of different courses, and analyzing the download entrance, access source and access time. The relevant data of download scenarios in different time periods are combined to generate a scenario classification data set, including: A data miner is used to parse the download source network address, port number and access path identifier from the original download sequence to obtain a user access feature table; Perform time series analysis on user behaviors according to the user access feature table to obtain a course resource access path transition probability matrix; Extract the download records of each time period according to the course resource access path transfer probability matrix, and calculate the time period feature vector including the total download amount, download frequency and maximum download amount per unit time; The time period feature vector is matched with the teaching activity time benchmark. If the feature vector index value exceeds the preset threshold range, it is determined to be the corresponding scene type and a scene classification data set is generated.
4. The method according to claim 1, characterized in that The clustering algorithm is used to analyze the download behavior of the compliance scenarios in the scenario classification data set. By extracting the behavioral characteristics of students accessing cross-course related course groups during the teaching discussion and review stages, a compliance behavior feature model that describes the normal download frequency and reasonable user distribution is obtained, including: Acquire initial access sequence data with a user identifier and an access timestamp according to the scene classification data set, wherein the initial access sequence data includes course number information; The initial access sequence data is processed by a sliding time window method to obtain a user access behavior time series feature table with a statistical value of the number of visited courses, wherein the user access behavior time series feature table includes adjacent access time differences; Marking the course groups according to the user access behavior time series feature table, wherein the course group marks are determined by extracting the course knowledge point association relationship in the teaching resource library to obtain a course group division table; The frequency distribution of users' course group visits in the discussion stage and the review stage is calculated according to the user access behavior time series feature table, and the density clustering method is used to obtain the user access pattern cluster center. The user access pattern cluster center is used to construct a user behavior feature vector, and a compliance behavior feature model is established based on the user behavior feature vector.
5. The method according to claim 1, characterized in that The anonymous download account of the non-compliant scenario is obtained, and an anomaly detection algorithm is used to identify behaviors that deviate from the compliant behavior feature model. If the download volume increases suddenly during the sensitive examination period, the user identity is single and concentrated, and the access is repeatedly switched between the question banks of different courses, then the download behavior is judged to be abnormal download, and the behavior features of the abnormal download behavior are extracted to generate an abnormal behavior feature model, including: Obtaining non-compliant scenario data with a download account identifier and a login time period, wherein the non-compliant scenario data is generated when the data is downloaded by an anonymous account; Extract the access source address and account creation time according to the non-compliant scenario data, and generate an account basic data table, wherein the account basic data table includes an account identifier and its basic feature items; Matching sensitive time periods with respect to the account basic data table, wherein the sensitive time periods are determined by the examination cycle schedule in the educational management database; An isolation forest algorithm is used to detect anomalies in access records during sensitive periods to obtain an anomaly indicator data table, which includes the total download volume and access duration of a single account. Extracting the course access sequence feature value according to the abnormal indicator data table, calculating the state transition probability matrix of the course access sequence through the Markov chain, extracting the course access state transition law, and constructing a user access behavior sequence model; The behavior deviation of each account is calculated based on the user access behavior sequence model, and the abnormal behavior feature model is constructed by combining the abnormal indicator data table.
6. The method according to claim 1, characterized in that The pre-built sandbox environment is monitored in real time based on the abnormal behavior feature model. If it is detected that the anonymous download account has a sudden increase in download volume and frequently cross-compared cross-course test questions during the sensitive examination period, it is determined that the sandbox boundary breach warning is triggered and a warning signal is generated, including: Obtaining an account behavior data stream in a sandbox environment, extracting access timestamps, the number of downloaded resources, and resource type numbers according to the data stream, and obtaining a real-time account behavior record table; Mark sensitive time intervals according to the real-time behavior record table of the account and the test cycle arrangement data, and filter the real-time behavior record table of the account by time segmentation tools to obtain a sensitive time monitoring data table; Constructing a monitoring indicator system including hourly download growth rate, test question access frequency and course repeat access rate for the sensitive time period monitoring data table, and generating a monitoring indicator threshold table using an abnormal behavior feature model; Calculate the real-time value of the monitoring indicator by comparing it with the monitoring indicator threshold table, perform weighted sum operation on the indicator deviation by feature fusion calculation method, and if the behavior score exceeds the warning threshold, trigger the boundary breach event to generate a warning data packet; It also includes: in the test resource access platform of the campus network, resource access rules based on user identity and course attributes are set at the permission control layer, test resources of different courses are logically isolated, dynamic threshold control modules are deployed at the resource call layer, the number and frequency of test downloads are restricted in real time, and data collection probes are implanted at the behavior monitoring layer to record the timing characteristics and access patterns of account operations, so as to build a three-level isolated test resource access sandbox environment.
7. The method according to claim 6, characterized in that In the test resource access platform of the campus network, resource access rules based on user identity and course attributes are set in the permission control layer, and test resources of different courses are logically isolated. A dynamic threshold control module is deployed in the resource call layer to limit the number and frequency of test downloads in real time. A data collection probe is implanted in the behavior monitoring layer to record the timing characteristics and access mode of account operations, so as to build a three-level isolated test resource access sandbox environment, including: Generate a user authority table based on the user identity authentication database, and obtain the user identity and the access rules of the course resources through the authority mapper. The access rules are obtained by the resource grouper after classifying the course test resources by subject. The resource isolator is deployed by adopting the access rule to establish an independent access domain for the course test question resources, wherein the independent access domain is formed by partitioning and storing the test question resources by the resource identification code; Calculate the access frequency reference value according to the historical access statistics data in the independent access domain, and set the resource call restriction rule according to the access frequency reference value, wherein the resource call restriction rule includes the upper limit of the download amount per unit time and the minimum access interval; A data collection probe is used to obtain the user access data flow in the independent access domain, and the behavior data including the access timestamp and the resource number are recorded. The behavior data is processed by a feature extractor and then stored in a behavior feature database.
8. The method according to claim 1, characterized in that The analysis of the warning signals and the sandbox environment security logs, if the resource usage rate suddenly increases, the permissions change frequently, and the network traffic soars, it is determined that the sandbox boundary has been maliciously breached, and the breach feature analysis results are obtained, including: Receive resource usage records, permission operation records, and network access records in the early warning signal library and the sandbox security log, and generate a security event data table based on the resource usage records, permission operation records, and network access records; Counting resource occupancy and authority modification frequency per unit time according to the security event data table, generating a resource occupancy status table through the resource occupancy, and generating an authority change frequency table through the authority modification frequency; A Gaussian mixture clustering method is used to identify abnormal intervals of network traffic data in the security event data table, and the results of abnormal interval identification are used to generate a traffic mutation situation table; The resource occupancy status table, the authority change frequency table and the traffic mutation status table are data-associated through a feature fusion device to obtain a multi-dimensional abnormal feature matrix. If the feature similarity score of the multi-dimensional abnormal feature matrix exceeds a breakthrough judgment threshold, a boundary breakthrough report is generated.
9. The method according to claim 1, characterized in that: The method of dynamically adjusting the sandbox security policy according to the breakthrough feature analysis results includes limiting the download permissions of abnormal anonymous accounts, isolating the surge in malicious traffic, and optimizing the allocation of surge resources. The method of dynamically adjusting the sandbox security policy is applied to the sandbox, including: A breakthrough quantifier is used to process the abnormal account identification list, malicious traffic characteristic values, and resource occupancy mutation point data to obtain security policy adjustment data including breakthrough level parameters, breakthrough range parameters, and breakthrough degree parameters; Calculate the permission adjustment parameter value according to the security policy adjustment data, generate the download number limit value, access interval limit value and operation permission limit value through the permission downgrade processor, and implement permission control on the accounts in the abnormal account identification list through the permission downgrade processor; The resource monitor is used to read the resource occupancy mutation point data, and the CPU usage upper limit, memory occupancy upper limit and storage space upper limit are calculated. The policy synthesizer is used to generate a sandbox security policy package containing permission restriction values, traffic restriction values and resource upper limit values.
Citation Information
Patent Citations
Attack and defense test method for network safety of power industry
CN105262771A
Cross-network security situation awareness and early warning notification system
CN118316741A