Information security tracking system based on network supervision requirements

By employing multi-dimensional network monitoring and intelligent analysis modules, combined with deep packet inspection and IP/domain name resolution tracing technologies, the complexity of network threats and risk assessment issues have been resolved, enabling intelligent monitoring and precise early warning of the network environment and reducing the workload of administrators.

CN119696925BActive Publication Date: 2025-12-09SHAANXI ENERGY VOCATIONAL & TECHNICAL COLLEGE +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510144686.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-12-09
Estimated Expiration
2045-02-10

AI Technical Summary

Technical Problem

Existing technologies are insufficient to comprehensively address complex and ever-changing network threats, cannot reasonably reflect network risks at different times, and have a low level of intelligence, making it difficult for administrators to plan and adjust monitoring solutions.

Method used

It employs a multi-dimensional network monitoring module, an intelligent analysis engine module, a threat early warning and response module, and a behavior tracking and tracing module, combined with technologies such as deep packet inspection, traffic analysis, IP tracing, domain name resolution tracing, and machine learning, to achieve comprehensive monitoring, intelligent analysis, and accurate early warning of the network environment.

Benefits of technology

It enables comprehensive monitoring, intelligent analysis, and efficient tracking of the network environment, allowing for reasonable assessment of network risks, reducing the workload of administrators, and improving the intelligence level of network supervision.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119696925B_ABST
    Figure CN119696925B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of network supervision, and specifically relates to an information security tracking system based on network supervision requirements, which comprises a multidimensional network monitoring module, an intelligent analysis engine module, a threat early warning response module, a behavior tracking and tracing module and an administrator terminal; the application integrates key technologies such as multidimensional monitoring, intelligent analysis, threat early warning, behavior tracking and data privacy protection, realizes comprehensive monitoring, intelligent analysis, accurate early warning and efficient tracking of the network environment, meets the increasingly complex network supervision requirements, determines high-risk periods and low-risk periods through period risk rating module for period risk rating analysis, is beneficial to the subsequent development of a reasonable and scientific network supervision scheme for different periods, and analyzes the network supervision condition of the detection period through the supervision analysis output module to timely strengthen the network supervision, thereby significantly reducing the work difficulty of the administrator.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network supervision, and specifically relates to an information security tracking system based on network supervision requirements. BACKGROUND

[0002] With the rapid development of the Internet, the network space has become an important carrier of social and economic activities, however, the increasing diversity and complexity of network threats have brought great challenges to network supervision;

[0003] Traditional network security systems often focus on single-dimensional protection, which is difficult to comprehensively respond to complex and variable network threats, and cannot reasonably feedback the network risk of each period and accurately evaluate the network supervision situation within a period of time, which is not conducive to the subsequent planning and adjustment of the administrator's supervision scheme, increases the difficulty of the administrator's work, and has low intelligence;

[0004] In view of the above technical defects, a solution is proposed. SUMMARY

[0005] The present application aims to provide an information security tracking system based on network supervision requirements, which solves the problem that the prior art is difficult to comprehensively respond to complex and variable network threats, and cannot reasonably feedback the network risk of each period and accurately evaluate the network supervision situation within a period of time, which is not conducive to the subsequent planning and adjustment of the administrator's supervision scheme, and has low intelligence.

[0006] To achieve the above-mentioned purpose, the present application provides the following technical scheme:

[0007] The information security tracking system based on network supervision requirements comprises a multi-dimensional network monitoring module, an intelligent analysis engine module, a threat early warning response module, a behavior tracking and tracing module and an administrator terminal.

[0008] The multi-dimensional network monitoring module monitors the multi-dimensional information of network traffic, user behavior and system logs in real time, and uses deep packet inspection and traffic analysis technology to comprehensively monitor the network environment, and sends the monitored data to the intelligent analysis engine module;

[0009] The intelligent analysis engine module deeply mines and analyzes the monitored data, and automatically identifies suspicious network activities, and sends the identified suspicious network activities to the threat early warning response module and the behavior tracking and tracing module;

[0010] The threat early warning response module automatically triggers the early warning mechanism based on the result of the intelligent analysis engine module, and sends the alarm to the administrator terminal through email, SMS or pop-up window, and provides emergency response plans and automatic disposal processes to respond to the corresponding suspicious network activities;

[0011] The behavior tracking and tracing module uses IP tracking and domain name resolution tracking technology to track and trace suspicious network activities, and sends the corresponding tracking and tracing results to the administrator terminal.

[0012] The specific operation process of the behavior tracking and tracing module includes:

[0013] IP tracking: by analyzing network traffic and logs, the IP address of suspicious network activity is determined, the geographical location information of the IP address is used to preliminarily locate the source of the suspicious activity, the change trajectory of the IP address is further tracked, and the attack path and jump point are analyzed;

[0014] Domain name resolution tracking: the domain names involved in suspicious network activities are resolved, the registration information and DNS resolution records of the domain names are obtained, the attack path and network architecture of the attacker are constructed by analyzing the resolution chain and associated domain names of the domain names, and the registrant, controller and the organization or individual behind the malicious domain name are identified and tracked;

[0015] Multi-dimensional data correlation: the results of IP tracking and domain name resolution tracking are associated with other data sources for correlation analysis, the correlation between different data sources is mined to discover potential security threats and the true identity of the attacker;

[0016] Behavior pattern analysis: in-depth analysis of the behavior pattern of suspicious network activities, including attack time, frequency and method, by comparing with known attack patterns and cases, the intention of the attacker is judged and the next action is predicted.

[0017] Further, the intelligent analysis engine module is in communication with the time period risk rating module, the intelligent analysis engine module sends the identified suspicious network activities to the time period risk rating module, the time period risk rating module divides each day into several time periods, and marks the corresponding time period as target time period i, and the value of i is greater than 4; through time period risk rating analysis, the target time period i is marked as a high-risk time period or a low-risk time period, and the marking information of the target time period i is sent to the administrator terminal.

[0018] Further, the specific analysis process of the time period risk rating analysis is as follows:

[0019] Set the detection period, and obtain the suspicious daily value of the target time period i in the corresponding date by analysis, compare the suspicious daily value with the preset suspicious daily threshold value, if the suspicious daily value exceeds the preset suspicious daily threshold value, assign a risk symbol FP-1 to the target time period i of the corresponding date;

[0020] The number of times that the target period i is assigned with the risk symbol FP-1 in the detection period is obtained and marked as a risk day frequency value, and the suspicious day condition values of the target period i in the detection period are averaged to obtain a suspicious comprehensive detection value, and the suspicious day condition value with the largest value corresponding to the target period i in the detection period is marked as a suspicious day amplitude value;

[0021] The period risk evaluation value is obtained through the risk day frequency value, the suspicious comprehensive detection value and the suspicious day amplitude value, and the period risk evaluation value is compared with a preset period risk evaluation threshold value, if the period risk evaluation value exceeds the preset period risk evaluation threshold value, the target period i is marked as a high-risk period, and if the period risk evaluation value does not exceed the preset period risk evaluation threshold value, the target period i is marked as a low-risk period.

[0022] Further, the analysis obtaining method of the suspicious day condition value is specifically as follows:

[0023] All suspicious network activities of the target period i in the corresponding date are obtained, the suspicious network activities of the target period i in the corresponding date are classified, and the number of occurrences of the suspicious network activities of the corresponding type in the target period i in the corresponding date is marked as a suspicious type frequency value;

[0024] A set of preset weight values corresponding to each type of suspicious network activity is set in advance, the product of the suspicious type frequency value of the corresponding type of suspicious network activity in the target period i in the corresponding date and the corresponding preset weight value is marked as a suspicious type detection value, and the suspicious type detection values of all types of suspicious network activities occurring in the target period i in the corresponding date are summed to obtain the suspicious day condition value.

[0025] Further, the period risk rating module is communicatively connected to a supervision analysis output module, the period risk rating module sends the marking information of the target period i to the supervision analysis output module, the supervision analysis output module analyzes the network supervision condition of the detection period, generates a supervision warning signal or a supervision safety signal through the analysis, and sends the supervision warning signal or the supervision safety signal to an administrator terminal.

[0026] Further, the specific analysis process of the supervision analysis output module includes:

[0027] The number of high-risk periods is obtained and marked as a high-risk detection value, and the period risk evaluation values of all periods are averaged to obtain a suspicious risk detection value, the high-risk detection value and the suspicious risk detection value are compared with a preset high-risk detection threshold value and a preset suspicious risk detection threshold value respectively, and if the high-risk detection value or the suspicious risk detection value exceeds the corresponding preset threshold value, a supervision warning signal is generated.

[0028] Further, if the high-risk detection value and the suspicious-risk detection value do not exceed the corresponding preset threshold value, the time when the corresponding suspicious network activity is identified is started to be counted, until the time when the threat of the corresponding suspicious network activity is eliminated, and the elimination time is obtained, and the elimination time is compared with the corresponding preset elimination time threshold value, if the elimination time exceeds the preset elimination time threshold value, the corresponding elimination time is marked as the elimination time;

[0029] The number of elimination times in the detection period is obtained and marked as an elimination detection value, and the exceeding value of the elimination time compared with the corresponding preset elimination time threshold value is marked as an elimination exceeding detection value, and all elimination exceeding detection values are averaged to obtain an elimination exceeding table value;

[0030] The optimized management evaluation value of the detection period is obtained, the supervision hidden danger value is obtained by numerically calculating the optimized management evaluation value, the high-risk detection value, the suspicious-risk detection value, the elimination detection value and the elimination exceeding table value, and the supervision hidden danger value is compared with the preset supervision hidden danger threshold value, if the supervision hidden danger value exceeds the preset supervision hidden danger threshold value, a supervision warning signal is generated; if the supervision hidden danger value does not exceed the preset supervision hidden danger threshold value, a supervision safety signal is generated.

[0031] Further, the supervision analysis output module is communicatively connected to the optimized management evaluation module, the optimized management evaluation module analyzes the optimized management condition of the system optimization in the detection period, obtains the optimized management evaluation value through the analysis, and sends the optimized management evaluation value of the detection period to the supervision analysis output module.

[0032] Further, the analysis method of the optimized management evaluation value is as follows:

[0033] All optimization times for system optimization in the detection period are collected, the interval time between adjacent two groups of optimization times is marked as an optimization interval value, the optimization interval value is compared with the preset optimization interval threshold value, and the corresponding optimization interval value is marked as an optimization interval exceeding value; the number of interval exceeding values in the detection period is counted and marked as an optimization interval exceeding value, all optimization interval values in the detection period are averaged to obtain an optimization interval condition value, the largest optimization interval value in the detection period is marked as an optimization interval amplitude value, and the optimization interval exceeding value, the optimization interval condition value and the optimization interval amplitude value are numerically calculated to obtain the optimized management evaluation value.

[0034] Compared with the prior art, the beneficial effects of the present application are:

[0035] 1. In this invention, a multi-dimensional network monitoring module comprehensively monitors the network environment, an intelligent analysis engine module deeply mines and analyzes the monitored data and automatically identifies suspicious network activities, a threat warning and response module automatically triggers a warning mechanism based on the results of the intelligent analysis engine module and provides emergency response plans and automated handling processes to deal with corresponding suspicious network activities, and a behavior tracking and tracing module uses network tracking technologies such as IP tracking and domain name resolution tracking to track and trace suspicious network activities, thus realizing comprehensive monitoring, intelligent analysis, accurate warning and efficient tracking of the network environment, meeting the increasingly complex network supervision needs;

[0036] 2. In this invention, the time-period risk rating module determines the high-risk and low-risk periods of each day based on time-period risk rating analysis. This is beneficial for formulating reasonable and scientific network monitoring plans for different time periods. Furthermore, the monitoring analysis output module analyzes the network monitoring status during the detection period and reminds the administrator to continuously strengthen network monitoring to ensure network information security when generating a monitoring warning signal. This significantly reduces the workload of the administrator and has a high degree of intelligence. Attached Figure Description

[0037] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings;

[0038] Figure 1 This is a system block diagram of Embodiment 1 of the present invention;

[0039] Figure 2 This is a system block diagram of Embodiments 2 and 3 of the present invention. Detailed Implementation

[0040] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0041] Example 1: As Figure 1 As shown, the information security tracking system based on network supervision requirements proposed in this invention includes a multi-dimensional network monitoring module, an intelligent analysis engine module, a threat early warning and response module, a behavior tracking and tracing module, and an administrator terminal;

[0042] The multi-dimensional network monitoring module monitors network traffic, user behavior, and system logs in real time, and uses deep packet inspection and traffic analysis technologies to comprehensively monitor the network environment, and sends the monitored data to the intelligent analysis engine module.

[0043] The intelligent analysis engine module integrates machine learning and big data analysis technologies, deeply mines and analyzes the monitored data, automatically identifies suspicious network activities, and sends the identified suspicious network activities to the threat early warning response module and the behavior tracking and tracing module.

[0044] The threat early warning response module automatically triggers an early warning mechanism based on the results of the intelligent analysis engine module, sends an alarm to the administrator terminal through various means such as email, SMS, or pop-up window, and provides emergency response plans and automated disposal processes to deal with the corresponding suspicious network activities, thereby helping administrators quickly respond to security incidents and reduce losses.

[0045] The behavior tracking and tracing module uses network tracking technologies such as IP tracking and domain name resolution tracking to track and trace suspicious network activities, and sends the corresponding tracking and tracing results to the administrator terminal. The specific operation process of the behavior tracking and tracing module is as follows:

[0046] IP tracking: By analyzing network traffic and logs, the IP address of suspicious network activities is determined, the geographical location information of the IP address is used to preliminarily locate the source of suspicious activities, and the variable trajectory of the IP address is further tracked to analyze its possible attack path and jump point.

[0047] Domain name resolution tracking: The domain names involved in suspicious network activities are resolved to obtain the registration information and DNS resolution records of the domain names, the resolution chain and associated domain names of the domain names are analyzed to construct the network architecture and attack path of the attacker, and the registrant, controller, and the organization or individual behind the malicious domain name are identified and tracked.

[0048] Multi-dimensional data correlation: The results of IP tracking and domain name resolution tracking are correlated with other data sources (such as social media, email, payment records, etc.) for correlation analysis, and by mining the correlation between different data sources, potential security threats and the true identity of the attacker are discovered.

[0049] Behavior pattern analysis: The behavior pattern of suspicious network activities is analyzed in depth, including attack time, frequency, and method, and by comparing with known attack patterns and cases, the intention of the attacker is judged and the next action taken by the attacker is predicted.

[0050] The present application integrates multi-dimensional monitoring, intelligent analysis, threat early warning, behavior tracking, and data privacy protection key technologies, realizes comprehensive monitoring, intelligent analysis, accurate early warning, and efficient tracking of the network environment, meets the increasingly complex network monitoring needs, and has important practical value and popularization prospects.

[0051] Embodiment two: as Figure 2As shown, the difference between the embodiment and embodiment one is that the intelligent analysis engine module is in communication connection with the time period risk rating module, the intelligent analysis engine module sends the identified suspicious network activities to the time period risk rating module, the time period risk rating module divides each day into several time periods, the length of each time period is the same, and the corresponding time period is marked as target time period i, and the value of i is greater than 4;

[0052] The target time period i is marked as a high-risk time period or a low-risk time period through the time period risk rating analysis, and the marking information of the target time period i is sent to the administrator terminal, so as to remind the administrator to strengthen the network supervision of the high-risk time period in the subsequent, which is beneficial to the subsequent reasonable and scientific formulation of the network supervision scheme for different time periods, reduces the work difficulty of the administrator, and has high intelligent degree; the specific analysis process of the time period risk rating analysis is as follows:

[0053] The detection period is set, preferably, the detection period is twenty-five days; all suspicious network activities of the target time period i in the corresponding date are obtained, all suspicious network activities of the target time period i in the corresponding date are classified (such as DDoS attack, phishing, malicious software propagation, illegal access attempt, data theft and leakage, etc.), and the occurrence frequency of the corresponding type of suspicious network activities in the target time period i in the corresponding date is marked as a suspicious class frequency value;

[0054] Each type of suspicious network activity corresponds to a group of preset weight values in advance, wherein the values of the preset weight values are positive numbers, and the greater the security threat degree brought by the corresponding type of suspicious network activity, the greater the value of the preset weight value matched therewith;

[0055] The product of the suspicious class frequency value of the corresponding type of suspicious network activity in the target time period i in the corresponding date and the corresponding preset weight value is marked as a suspicious class detection value, and the suspicious class detection values of all types of suspicious network activities occurring in the target time period i in the corresponding date are summed to obtain a suspicious daily condition value, the suspicious daily condition value is compared with a preset suspicious daily condition threshold value, if the suspicious daily condition value exceeds the preset suspicious daily condition threshold value, it indicates that the target time period i of the corresponding date is subjected to greater network risk, and then the risk symbol FP-1 is assigned to the target time period i of the corresponding date;

[0056] The number of times that the target time period i is assigned with the risk symbol FP-1 in the detection period is obtained and marked as a risk daily frequency value, and the mean value of all suspicious daily condition values of the target time period i in the detection period is calculated to obtain a suspicious comprehensive detection value, and the suspicious daily condition value corresponding to the maximum value of the target time period i in the detection period is marked as a suspicious daily amplitude value;

[0057] The risk assessment value LSi is obtained by numerically calculating the risk daily frequency value LWi, the suspicious comprehensive inspection value LPi, and the suspicious daily amplitude value LMi using the formula LSi=hg1*LWi+(hg2*LPi+hg3*LMi) / 2. Here, hg1, hg2, and hg3 are preset proportional coefficients with values ​​greater than zero. Furthermore, the larger the value of the risk assessment value LSi, the greater the overall network risk experienced during the target time period i each day.

[0058] The time period risk assessment value LSi is compared with the preset time period risk assessment threshold. If the time period risk assessment value LSi exceeds the preset time period risk assessment threshold, it indicates that the overall network risk in the target time period i is relatively large, and the target time period i is marked as a high-risk time period. If the time period risk assessment value LSi does not exceed the preset time period risk assessment threshold, it indicates that the overall network risk in the target time period i is relatively small, and the target time period i is marked as a low-risk time period.

[0059] Example 3: Figure 2 As shown, the difference between this embodiment and Embodiment 1 and Embodiment 2 is that the time period risk rating module is connected to the regulatory analysis output module. The time period risk rating module sends the marking information of the target time period i to the regulatory analysis output module. The regulatory analysis output module analyzes the network regulatory status during the detection period and generates a regulatory warning signal or a regulatory safety signal through analysis.

[0060] Furthermore, it sends regulatory warning signals or regulatory security signals to the administrator terminal. When the administrator terminal receives a regulatory warning signal, it reminds the administrator to continuously strengthen network supervision and adjust the network supervision plan in a timely manner, thereby ensuring network information security. The specific analysis process of the regulatory analysis output module is as follows:

[0061] The system acquires the number of high-risk periods and marks them as high-risk detection values. It also calculates the suspicious risk value by averaging the risk assessment values ​​of all periods. The high-risk detection value and the suspicious risk value are compared with the preset high-risk detection threshold and the preset suspicious risk detection threshold, respectively. If the high-risk detection value or the suspicious risk value exceeds the corresponding preset threshold, it indicates that the network threat during the detection period is relatively large and subsequent network supervision needs to be strengthened. In this case, a regulatory warning signal is generated.

[0062] If neither the high-risk detection value nor the suspicious detection value exceeds the corresponding preset threshold, the timer starts when the corresponding suspicious network activity is identified and continues until the threat of the corresponding suspicious network activity is eliminated. The elimination time is obtained accordingly. The elimination time is compared with the corresponding preset elimination time threshold. If the elimination time exceeds the preset elimination time threshold, it indicates that the response efficiency to the corresponding suspicious network activity is relatively slow. The corresponding elimination time is then marked as the risk elimination time.

[0063] The number of risk elimination times during the detection period is obtained and marked as risk elimination detection values. The excess value of the risk elimination time compared with the corresponding preset risk elimination time threshold is marked as risk elimination over-detection value. The average value of all risk elimination over-detection values ​​is calculated to obtain the risk elimination over-table value, and the optimized management evaluation value TN for the detection period is obtained.

[0064] Through formula The regulatory risk value TL is obtained by numerically calculating the optimized management assessment value TN, high-risk detection value TX, suspected risk detection value TF, risk elimination detection value TW, and risk elimination excess value TS. Among them, c1, c2, c3, c4, and c5 are preset proportional coefficients with values ​​greater than zero. Furthermore, the larger the value of the regulatory risk value TL, the greater the overall network regulatory risk during the detection period.

[0065] The regulatory risk value TL is compared with the preset regulatory risk threshold. If the regulatory risk value TL exceeds the preset regulatory risk threshold, it indicates that the overall network regulatory risk during the detection period is relatively large, and a regulatory warning signal is generated. If the regulatory risk value TL does not exceed the preset regulatory risk threshold, it indicates that the overall network regulatory risk during the detection period is relatively small, and a regulatory safety signal is generated.

[0066] Furthermore, the regulatory analysis output module communicates with the optimization management evaluation module. The optimization management evaluation module analyzes the optimization management status of the system during the detection period, obtaining an optimization management evaluation value (TN) through analysis. This TN value is then sent to the regulatory analysis output module. This not only accurately reflects the optimization management status of the system during the detection period but also provides data support for the regulatory analysis output module's analysis process, ensuring the accuracy of its analysis results. The specific method for obtaining the optimization management evaluation value is as follows:

[0067] All optimization moments for system optimization during the detection period are collected. The interval between two adjacent sets of optimization moments is marked as the optimization interval value. The optimization interval value is compared with the preset optimization interval threshold. If the optimization interval value exceeds the preset optimization interval threshold, the corresponding optimization interval value is marked as the optimization interval exceedance value.

[0068] The number of intervals exceeding the standard during the detection period is counted and marked as optimized interval values. The average of all optimized interval values ​​during the detection period is calculated to obtain the optimized interval value. The optimized interval value with the largest value during the detection period is marked as the optimized interval amplitude value.

[0069] and the optimized tube evaluation value TN is obtained by numerically calculating the optimized isofar value XF, the optimized isobar value XL and the optimized isobar amplitude value XP through the formula TN=ny1*XF+(ny2*XL+ny3*XP) / 2; wherein, ny1, ny2, ny3 are preset proportion coefficients, ny1>ny2>ny3>0; and the greater the value of the optimized tube evaluation value TN is, the worse the comprehensive performance of the system optimization management in the detection period is, and the less favorable it is to ensure network information security.

[0070] The working principle of the application is as follows: when in use, the network environment is comprehensively monitored by the multi-dimensional network monitoring module, the intelligent analysis engine module performs deep mining and analysis on the monitored data and automatically identifies suspicious network activities, the threat early warning response module automatically triggers the early warning mechanism and provides emergency response plans and automatic disposal processes to deal with the corresponding suspicious network activities based on the results of the intelligent analysis engine module, the behavior tracking and tracing module traces and traces the suspicious network activities by using network tracking technologies such as IP tracking and domain name resolution tracking, and integrates key technologies such as multi-dimensional monitoring, intelligent analysis, threat early warning, behavior tracking and data privacy protection, thereby realizing comprehensive monitoring, intelligent analysis, accurate early warning and efficient tracking of the network environment, meeting the increasingly complex network supervision needs, having important practical value and promotion prospects, and through the time period risk rating module, each day is divided into a plurality of time periods, the high-risk time period and the low-risk time period are determined based on the time period risk rating analysis, which is beneficial to subsequently reasonably and scientifically formulating a network supervision scheme for different time periods, and through the supervision analysis output module, the network supervision status in the detection period is analyzed, the administrator is reminded to continuously strengthen network supervision to ensure network information security when generating a supervision early warning signal, the work difficulty of the administrator is significantly reduced, and the intelligent degree is high.

[0071] The above formulas are all dimensionless numerical calculations, the formula is obtained by collecting a large amount of data to simulate a formula of the most recent real situation, and the preset parameters in the formula are set by a person skilled in the art according to the actual situation. The preferred embodiments disclosed above are only used to help explain the application. The preferred embodiments do not describe all the details and limit the application to the specific embodiments. Obviously, many modifications and changes can be made according to the content of the specification. The embodiments are selected and specifically described in the specification in order to better explain the principles and practical applications of the application, so that those skilled in the art can well understand and utilize the application. The application is limited by the claims and their entire scope and equivalents.

Claims

1. An information security tracking system based on network monitoring requirements, characterized by, The system comprises a multi-dimensional network monitoring module, an intelligent analysis engine module, a threat early warning response module, a behavior tracking and tracing module, and an administrator terminal. The multi-dimensional network monitoring module monitors multi-dimensional information of network traffic, user behavior, and system logs in real time, comprehensively monitors the network environment by using deep packet inspection and traffic analysis technology, and sends the monitored data to the intelligent analysis engine module. The intelligent analysis engine module deeply mines and analyzes the monitored data, automatically identifies suspicious network activities, and sends the identified suspicious network activities to the threat early warning response module and the behavior tracking and tracing module. The threat early warning response module automatically triggers an early warning mechanism based on the results of the intelligent analysis engine module, sends an alarm to the administrator terminal by email, SMS, or pop-up window, and provides an emergency response plan and an automatic disposal process to deal with the corresponding suspicious network activities. The behavior tracking and tracing module uses IP tracking and domain name resolution tracking technology to track and trace suspicious network activities, and sends the corresponding tracking and tracing results to the administrator terminal. The intelligent analysis engine module is communicatively connected to a time period risk rating module, and the intelligent analysis engine module sends the identified suspicious network activities to the time period risk rating module. The time period risk rating module divides each day into several time periods, marks the corresponding time period as target time period i, and i is greater than 4. The target time period i is marked as a high-risk time period or a low-risk time period through time period risk rating analysis, and the marking information of the target time period i is sent to the administrator terminal. The specific analysis process of the time period risk rating analysis is as follows: Set a detection period, obtain the suspicious daily condition value of the target time period i in the corresponding date by analysis, compare the suspicious daily condition value with the preset suspicious daily condition threshold, if the suspicious daily condition value exceeds the preset suspicious daily condition threshold, assign a risk symbol FP-1 to the target time period i of the corresponding date; Obtain the number of times the target time period i is assigned the risk symbol FP-1 in the detection period and mark it as a risk daily frequency value, and calculate the mean value of all suspicious daily condition values of the target time period i in the detection period to obtain a suspicious comprehensive detection value, and mark the suspicious daily condition value corresponding to the maximum value of the target time period i in the detection period as a suspicious daily amplitude value; Obtain the time period risk evaluation value through the risk daily frequency value, the suspicious comprehensive detection value, and the suspicious daily amplitude value, if the time period risk evaluation value exceeds the preset time period risk evaluation threshold, mark the target time period i as a high-risk time period; 2.The network monitoring demand based information security tracking system of claim 1, wherein, If the time period risk evaluation value does not exceed the preset time period risk evaluation threshold, mark the target time period i as a low-risk time period. The specific operation process of the behavior tracking and tracing module includes: IP tracking: by analyzing network traffic and logs, determine the IP address of suspicious network activities, use the geographical location information of the IP address to preliminarily locate the source of suspicious activities, further track the movement trajectory of the IP address, and analyze the attack path and jump point; Domain name resolution tracking: Resolve the domain names involved in suspicious network activities, obtain the registration information and DNS resolution records of the domain names, and through the analysis of the resolution chain and associated domain names, construct the network architecture and attack path of the attacker, identify and track the registrant, controller and the organization or individual behind the malicious domain name; Multi-dimensional data correlation: Correlate the results of IP tracking and domain name resolution tracking with other data sources, and through the mining of the correlation between different data sources, discover potential security threats and the real identity of the attacker; Behavior pattern analysis: In-depth analysis of the behavior patterns of suspicious network activities, including attack time, frequency and method, by comparing with known attack patterns and cases, to judge the intention of the attacker and predict the next action they will take. 3.The information security tracking system based on network monitoring requirements according to claim 1, wherein, The analysis method of the suspicious daily situation value is as follows: All suspicious network activities in the target period i of the corresponding date are obtained, and all suspicious network activities in the target period i of the corresponding date are classified, and the occurrence frequency of the corresponding type of suspicious network activity in the target period i of the corresponding date is marked as a suspicious class frequency value; A set of preset weight values corresponding to each type of suspicious network activity is set in advance, and the product of the suspicious class frequency value of the corresponding type of suspicious network activity in the target period i of the corresponding date and the corresponding preset weight value is marked as a suspicious class detection value, and the sum of the suspicious class detection values of all types of suspicious network activities occurring in the target period i of the corresponding date is calculated to obtain the suspicious daily situation value. 4.The information security tracking system based on network monitoring requirements according to claim 2, wherein, The period risk rating module is communicatively connected to the supervision analysis output module, and the period risk rating module sends the target period i marking information to the supervision analysis output module. The supervision analysis output module analyzes the network supervision situation of the detection period, generates a supervision warning signal or a supervision safety signal through analysis, and sends the supervision warning signal or the supervision safety signal to the administrator terminal. 5.The information security tracking system based on network monitoring requirements according to claim 4, wherein, The specific analysis process of the supervision analysis output module includes: The number of high-risk periods is obtained and marked as a high-risk detection value, and the average of the period risk evaluation values of all periods is calculated to obtain a suspicious risk detection value. If the high-risk detection value or the suspicious risk detection value exceeds the corresponding preset threshold, a supervision warning signal is generated. 6.The information security tracking system based on network monitoring requirements according to claim 5, wherein, If the high-risk detection value and the suspicious risk detection value do not exceed the corresponding preset threshold, the time is counted when the corresponding suspicious network activity is identified, and the time is counted until the threat of the corresponding suspicious network activity is eliminated. Accordingly, the elimination time is obtained, and the elimination time is compared with the corresponding preset elimination time threshold value. If the elimination time exceeds the preset elimination time threshold value, the corresponding elimination time is marked as a risk elimination time; The number of risk elimination times in the detection period is obtained and marked as a risk elimination detection value, and the excess value of the risk elimination time compared with the corresponding preset elimination time threshold value is marked as a risk elimination excess detection value, and the average of all risk elimination excess detection values is calculated to obtain a risk elimination excess table value; The optimization management evaluation value of the detection period is obtained, and the supervision hidden danger value is obtained by numerically calculating the optimization management evaluation value, the high-risk detection value, the suspicious risk detection value, the risk elimination detection value and the risk elimination excess table value. If the supervision hidden danger value exceeds the preset supervision hidden danger threshold, a supervision warning signal is generated; If the regulatory risk value does not exceed the preset regulatory risk threshold, a regulatory safety signal is generated. 7.The information security tracking system based on network monitoring requirements according to claim 4, wherein, The regulatory analysis output module is communicatively connected to an optimization management evaluation module. The optimization management evaluation module analyzes optimization management conditions for system optimization in a detection period, obtains an optimization management evaluation value through the analysis, and sends the optimization management evaluation value in the detection period to the regulatory analysis output module. 8.The information security tracking system based on network monitoring requirements according to claim 7, wherein, The analysis method of the optimization management evaluation value is as follows: All optimization time points for system optimization in the detection period are collected. The interval duration between two adjacent optimization time points is marked as an optimization interval value. If the optimization interval value exceeds a preset optimization interval threshold, the corresponding optimization interval value is marked as an optimization interval exceeding value. The number of interval exceeding values in the detection period is counted and marked as an optimization interval heterogeneity value. The mean value of all optimization interval values in the detection period is calculated to obtain an optimization interval condition value. The largest optimization interval value in the detection period is marked as an optimization interval amplitude value. The optimization interval heterogeneity value, the optimization interval condition value, and the optimization interval amplitude value are calculated to obtain the optimization management evaluation value.

Citation Information

Patent Citations

  • Network threat detection method and system based on artificial intelligence, and medium

    CN118590314A

  • SSL encrypted traffic attack behavior intelligent identification system based on deep packet detection

    CN118694575A

  • Adaptive network security early warning system and method based on deep learning

    CN119276543A