A network IP traffic security detection and protection system

By adopting real-time monitoring and user analysis units in the network security detection system, using neural network intelligent model and feature data analysis, the problem of difficult to identify user specific behaviors in the existing technology is solved, and the accurate identification and blocking of user abnormal behaviors is achieved, which improves the accuracy and reliability of detection.

CN119675995BActive Publication Date: 2025-05-16HANGZHOU JIEJING SCI & TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510185722.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-16
Estimated Expiration
2045-02-20

AI Technical Summary

Technical Problem

The prior art is difficult to accurately identify the specific behavior of users in network security detection, and lacks an identification method based on the user's personal habits.

Method used

Real-time monitoring unit and user analysis unit are used to monitor and analyze the user's real-time behavior using an intelligent model based on neural network structure. Combined with identifying feature data in the database, behavior evaluation is performed through discrete ratios and aggregated signals, abnormal points are marked and blocked.

Benefits of technology

It realizes accurate identification of user abnormal behavior, combines the user's usual access behavior, eliminates some abnormalities, which is more in line with user laws, and improves the accuracy and reliability of network security detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675995B_ABST
    Figure CN119675995B_ABST
Patent Text Reader

Abstract

The invention discloses a network IP traffic security detection and protection system, which relates to the technical field of network security. With the help of a user analysis unit, when the user is an old user, the real-time behavior of the user is monitored with the help of an intelligent model built based on a neural network structure in an identification database, and the specific behavior with abnormality is obtained, and it is marked as an abnormal point; then the abnormal point is compared with the characteristic data of generating discrete signals or aggregated signals stored in the identification database, and the number of abnormal points that have generated discrete signals is obtained, and the number is divided by the total number of abnormal points to obtain a discrete ratio. When the discrete ratio exceeds a preset value B2, a suspected signal is generated, otherwise the corresponding user real-time behavior is marked as a banned behavior; thereby achieving the ability to accurately identify the abnormal points of the user, and synchronously combining the user's usual access behavior, if the user's access behavior does not have an aggregated regularity, some abnormalities will be excluded to make it more in line with the user's regularity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of IP flow security detection, and in particular is a network IP flow security detection and protection system. Background Art

[0002] The patent with publication number CN116232774A discloses a network path analysis system and method for network security anomaly detection, wherein the method includes the following steps: performing traffic coloring and filtering on the target network, and performing network flow anomaly analysis; setting a test model, performing network attack detection on the target network, and obtaining detection data; attacking the test model in turn, obtaining attack data, and performing network path anomaly analysis; calculating the comprehensive score of the target network, and comprehensively evaluating the network topology vulnerability of the target network. Compared with the prior art, the present invention can objectively and comprehensively evaluate the network topology vulnerability of the target network, improve the accuracy of network anomaly detection, and at the same time improve the reliability of network security analysis.

[0003] However, for network security detection, how to better identify specific user behaviors? The existing technology is basically based on threat databases for recognition, but this may produce an incomplete understanding of user behaviors, and there is no way to identify user behaviors based on the user's personal habits. Based on this, a solution is provided. Summary of the invention

[0004] The present invention aims to solve at least one of the technical problems existing in the prior art;

[0005] To this end, the present invention proposes a network IP traffic security detection and protection system, comprising:

[0006] The real-time monitoring unit is used to monitor the real-time behavior of users when accessing the network, and transmit the users and their real-time behaviors to the user analysis unit. When the user is an old user, the user analysis unit monitors the real-time behavior of the user with the help of the intelligent model built based on the neural network structure in the identification database, obtains the specific behavior where the abnormality occurs, and marks it as an abnormal point; then the abnormal point is compared with the characteristic data generated by discrete signals or aggregated signals stored in the identification database, and the number of abnormal points that have generated discrete signals is obtained, which is divided by the total number of abnormal points to obtain a discrete ratio. When the discrete ratio exceeds the preset value B2, a suspected signal is generated, otherwise the corresponding user real-time behavior is marked as a banned behavior.

[0007] Furthermore, when the user is a newly added user, the user analysis unit will automatically connect to the threat intelligence library to analyze the user's real-time behavior. When a threatening behavior is identified, the user's real-time behavior will be automatically marked as a banned behavior.

[0008] Furthermore, the user analysis unit identifies the user as a new or old user in the following manner:

[0009] When it is detected that there is feature data of a related user in the identification database, a model recognition signal is generated, indicating that this user has past data and is not a new user. Otherwise, it means that this is a new user, and an intelligence recognition signal is generated.

[0010] Furthermore, a discrete signal or an aggregated signal is attached to any feature data.

[0011] Furthermore, the discrete signal or aggregate signal of the user's characteristic data is analyzed and obtained in the following manner:

[0012] Filter out data whose characteristic data is numerical, and then obtain any characteristic data. According to the characterization stable value of the discrete degree of several numerical values ​​of the characteristic data, compare it with the set threshold X1. If it exceeds X1, a discrete signal is generated, otherwise an aggregate signal is generated.

[0013] Furthermore, for data whose characteristic data is not a numerical value, the corresponding data is first assigned an identification number, which is unique, and then the number of occurrences of each identification number is obtained, marked as the number of occurrences, and then the mean of all occurrences is calculated and marked as the average number of occurrences. The number of identification numbers whose absolute value of the difference between the number of occurrences of the identification number and the average number of occurrences exceeds the preset value X2 is screened out, divided by the total number and marked as the out-of-box ratio. The characteristic data whose out-of-box ratio exceeds the set ratio B2 generates a discrete signal, otherwise an aggregate signal is generated.

[0014] Furthermore, the user's characteristic data is intercepted by a data interception unit, and the characteristic data includes IP address, port number, protocol type, access frequency, access time, common applications and common services; the data interception unit is used to transmit the characteristic data of the corresponding user to the behavior analysis unit.

[0015] Furthermore, the intelligent model is constructed as follows:

[0016] Collect characteristic data of users' online behavior, including samples of normal and abnormal behavior;

[0017] Marking the characteristic values ​​of several normal behaviors as normal characteristic data, and marking the characteristic values ​​of several abnormal behaviors as abnormal characteristic data; then randomly selecting 80% of the several normal characteristic data as a training set, and then mixing the remaining normal characteristic data and abnormal characteristic data to form a test set;

[0018] Select the initial intelligence model;

[0019] The initial intelligent model is trained using the training set. After the training is completed, the model is tested using the test set. If the recognition success rate is lower than the set value B1, B1 is generally 0.95. At this time, the data of the training set will be reselected and the parameters of the model will be adjusted until the success rate exceeds B1 to obtain a trained recognition model.

[0020] Furthermore, the initial intelligent model is a neural network structure, specifically:

[0021] Select a fully connected neural network or a multilayer perceptron as the neural network structure; select mean square error as the loss function to measure the difference between the model's predicted value and the actual value;

[0022] Choose gradient descent or other optimization algorithm for parameter update.

[0023] Compared with the prior art, the present invention has the following beneficial effects:

[0024] The present application uses a user analysis unit. When the user is an old user, the user's real-time behavior is monitored by an intelligent model built based on a neural network structure in an identification database, and specific abnormal behaviors are obtained and marked as abnormal points; then the abnormal points are compared with the characteristic data for generating discrete signals or aggregated signals stored in the identification database, and the number of abnormal points that have generated discrete signals is obtained, which is divided by the total number of abnormal points to obtain a discrete ratio. When the discrete ratio exceeds a preset value B2, a suspected signal is generated, otherwise the corresponding user real-time behavior is marked as a banned behavior; thereby achieving the ability to accurately identify the user's abnormal points and simultaneously combine the user's normal access behavior. If the user's access behavior does not have an aggregated regularity, some abnormalities will be eliminated to make it more in line with the user's regularity; the present invention is simple, effective, and easy to use. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 is a system block diagram of the present invention;

[0026] Figure 2 This is a flowchart of the analysis of discrete signals or aggregated signals of the present invention. DETAILED DESCRIPTION

[0027] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0028] See also Figure 1-Figure 2 ,This application provides a network IP traffic security detection and protection system, including;

[0029] The data interception unit is used to intercept the user's characteristic data, which generally includes IP address, port number, protocol type, access frequency, access time, common applications and common services, etc., and the characteristic data that can represent the user's preference type, and transmit the corresponding user's characteristic data to the behavior analysis unit. The behavior analysis unit is used to perform habit interception on the user and its characteristic data. The specific method of habit interception is:

[0030] Get all the user's feature data, which includes several feature data. Each feature data has different specific performances each time the user visits. Filter the feature data. First, select all data with numerical features, such as access frequency, access duration, etc. Of course, it can also be other data. This is just an example.

[0031] Then, any feature data is obtained and marked as Ti, i=1, ..., n, and then the mean value P of Ti is automatically obtained, and its stable value W is calculated using the formula. The specific calculation formula is:

[0032] ;

[0033] When the W value does not exceed X1, an aggregate signal is generated, and X1 is a preset value, otherwise a discrete signal is generated;

[0034] For non-numerical data, such as users' frequently used applications and services, we first quantify the data and assign a unique identification number to the corresponding data. Then, we obtain the number of occurrences of each identification number and mark it as the number of occurrences. Then, we calculate the mean of all the occurrences and mark it as the average number of occurrences. Then, we set a filter box. The value range of the filter box is filter box = average number of occurrences ± X2, where X2 is a preset value.

[0035] Then, the number of identification numbers that do not meet the filter box is obtained, and it is divided by the total number of identification numbers. The obtained mark is the out-of-box ratio. When the out-of-box ratio exceeds the set ratio B1, a discrete signal is generated, otherwise an aggregate signal is generated. B1 is generally set to 0.4;

[0036] Obtain all the characteristic data of the user and the corresponding discrete signals or aggregated signals, perform the same process on the remaining users, and obtain the characteristic data of all users and the corresponding discrete signals or aggregated signals;

[0037] Then train the intelligent model to identify abnormal user behavior. The intelligent model is constructed as follows:

[0038] It is necessary to collect sufficient characteristic data representing users' online behavior, including samples of normal and abnormal behavior;

[0039] Extract useful features from raw data, such as access frequency, browsing time, visited page types, etc.;

[0040] Encoding non-numeric features, such as One-Hot Encoding, so that neural network models can understand and process them;

[0041] Scale the feature values ​​to a uniform range to improve the training efficiency and accuracy of the model; mark the feature values ​​of several normal behaviors as normal feature data, and mark the feature values ​​of several abnormal behaviors as abnormal feature data; then randomly select 80% of the normal feature data as the training set, and then mix the remaining normal feature data and abnormal feature data to form a test set;

[0042] Choose a fully connected neural network or a multilayer perceptron (MLP) as the neural network structure; choose Mean Squared Error as the loss function to measure the difference between the model's predicted value and the actual value; choose Gradient Descent or other optimization algorithms for parameter update;

[0043] Use the training set to train the model, including steps such as forward propagation, loss calculation, backpropagation, and parameter update;

[0044] Then the model is tested using the test set. If the recognition success rate is lower than the set value B1, which is generally 0.95, the training set data will be reselected and the model parameters will be adjusted until the success rate exceeds B1, thus obtaining a trained recognition model.

[0045] Obtaining the recognition model and the characteristic data of all users generating discrete signals or aggregated signals;

[0046] The behavior analysis unit is used to transmit the recognition model, the feature data of the generated discrete signal or the aggregated signal to the recognition database; the recognition database receives and stores the recognition model, the feature data of the generated discrete signal or the aggregated signal transmitted by the behavior analysis unit;

[0047] The real-time monitoring unit is used to monitor the real-time behavior of users when accessing the network, and transmit the users and their real-time behavior to the user analysis unit. After receiving the users and their real-time behavior, the user analysis unit analyzes them. The specific analysis method is as follows:

[0048] First, the user is acquired. When there is feature data of a related user that generates a discrete signal or an aggregate signal, a model recognition signal is generated, indicating that this user has past data and is not a new user. Otherwise, it means that this user is a new user, and an intelligence recognition signal is generated at this time.

[0049] When the model recognition signal is generated, the user's real-time behavior will be monitored and analyzed with the help of the intelligent model, and the specific abnormal behavior will be obtained and marked as anomaly points. Then all the anomaly points will be compared with the characteristic data to obtain the number of anomaly points that have generated discrete signals, which will be divided by the total number of anomaly points to obtain the discrete ratio. When the discrete ratio exceeds B2, B2 is a preset value, generally 0.3, and of course it can be set to other values ​​according to the needs of the administrator. At this time, a suspected signal is generated, otherwise the corresponding user's real-time behavior will be marked as a banned behavior; when a suspected signal is generated, it is necessary to further observe the behavior of the corresponding user and not process it for the time being;

[0050] When an intelligence identification signal is generated, the threat intelligence database will be automatically connected to analyze the user's real-time behavior. When a threatening behavior is identified, the user's real-time behavior will be automatically marked as a banned behavior.

[0051] The threat database stores the threat behaviors of several users. The threat database can be obtained through open source blacklists on the Internet, such as FireHOL, sans.edu, etc. These blacklists are updated quickly and have high credibility. The threat behaviors of users can also be obtained through the threat intelligence platform that provides comprehensive threat intelligence query and sharing functions, such as Weibo Online, 360 Threat Intelligence Center, Qi'anxin Threat Intelligence Center, Anheng Threat Intelligence Center, etc.

[0052] The behavior analysis unit is used to transmit the blocking behavior and its corresponding user integration to the execution unit, and the execution unit is used to stop the access behavior of the corresponding user.

[0053] Some of the data in the above formula are calculated by removing the dimensions and taking their numerical values. The formula is a formula that is closest to the actual situation obtained by software simulation of a large amount of collected data; the preset parameters and preset thresholds in the formula are set by technical personnel in this field according to actual conditions or obtained through simulation of a large amount of data.

[0054] The above embodiments are only used to illustrate the technical method of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A network IP traffic security detection and protection system, characterized in that: include: A real-time monitoring unit is used to monitor the real-time behavior of users when accessing the network; A user analysis unit, receiving user and real-time behavior information transmitted by the real-time monitoring unit; When the user is an old user, the user analysis unit monitors the user's real-time behavior with the help of an intelligent model built based on a neural network structure in the recognition database, obtains specific abnormal behaviors, and marks them as abnormal points; compares the abnormal points with the feature data that generates discrete signals or aggregated signals stored in the recognition database, obtains the number of abnormal points that have generated discrete signals, and then divides it by the total number of abnormal points to obtain a discrete ratio; When the discrete ratio exceeds the preset value B2, a suspicious signal is generated, otherwise the corresponding user real-time behavior is marked as a banned behavior; The discrete signal or aggregate signal of the user's characteristic data is analyzed in the following way: Filter out data whose characteristic data is numerical value; Then, any characteristic data is obtained from the screened data, and the stable value is characterized according to the discrete degree of several values ​​of the characteristic data; The stable value is compared with the set threshold value X1; If the stable value exceeds X1, a discrete signal is generated, otherwise an aggregate signal is generated; For data whose characteristic data is not numerical, discrete signals or aggregate signals are analyzed in the following way: First, the corresponding data is assigned an identification number, which is unique; Then get the number of times each identification number appears and mark it as the number of occurrences; Calculate the mean of all occurrences and mark it as the average occurrence; Filter out the number of identification digits whose absolute value of the difference between the number of times the identification digit appears and the average number of times exceeds the preset value X2, and then divide the number by the total number and mark it as the out-of-frame ratio; The feature data whose orbital-to-extraorbital ratio exceeds the set ratio B2 generates a discrete signal, otherwise an aggregate signal is generated.

2. A network IP traffic security detection and protection system according to claim 1, characterized in that: When the user is a newly added user, the user analysis unit automatically connects to the threat intelligence library to analyze the user's real-time behavior. When a threatening behavior is identified, the user's real-time behavior is automatically marked as a banned behavior.

3. A network IP traffic security detection and protection system according to claim 1, characterized in that: The user analysis unit identifies users as new and old users in the following ways: When it is detected that there is feature data of a related user in the identification database, a model identification signal is generated, indicating that this user has past data and is not a new user. Otherwise, it indicates that the user is a new user and an intelligence identification signal is generated.

4. A network IP traffic security detection and protection system according to claim 3, characterized in that: Any feature data is attached with discrete or aggregated signals.

5. A network IP traffic security detection and protection system according to claim 4, characterized in that: The user's characteristic data is intercepted by the data interception unit, and the characteristic data includes IP address, port number, protocol type, access frequency, access time, common applications and common services; the data interception unit is used to transmit the characteristic data of the corresponding user to the behavior analysis unit.

6. A network IP traffic security detection and protection system according to claim 1, characterized in that: The smart model is constructed as follows: Collect characteristic data of users' online behavior, including samples of normal and abnormal behavior; Marking a number of normal behavior feature values ​​as normal feature data, and marking a number of abnormal behavior feature values ​​as abnormal feature data; Randomly select 80% of the normal feature data as the training set, and then mix the remaining normal feature data and abnormal feature data to form a test set; Select the initial intelligence model; The initial intelligent model is trained using the training set. After the training is completed, the model is tested using the test set. If the recognition success rate is lower than the set value B1, the data of the training set will be reselected and the parameters of the model will be adjusted until the success rate exceeds B1 to obtain a trained recognition model.

7. A network IP traffic security detection and protection system according to claim 6, characterized in that: The initial intelligent model is a neural network structure, specifically: Select a fully connected neural network or a multilayer perceptron as the neural network structure; select mean square error as the loss function to measure the difference between the model's predicted value and the actual value; Select the gradient descent algorithm for parameter update.

Citation Information

Patent Citations

  • Network path analysis system and method for network security anomaly detection

    CN116232774A

  • DDoS attack detection method, system, device and medium

    CN115714685A

  • Information processing method and system based on artificial intelligence analysis

    CN115906160A