Methods for processing network traffic data, computer devices and storage media

By identifying the categories of network traffic data and applying matching processing strategies, this solves the problem that static policies in existing IPsec cannot cope with complex network environments, achieving fine-grained encryption and improving the flexibility and efficiency of security management.

CN119728275BActive Publication Date: 2025-12-02BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411953593.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-12-02
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

In existing IPsec implementations, the fixed and static security policies lead to all traffic being processed in the same way, which cannot cope with complex network environments and application scenarios, resulting in performance overhead or unmet security requirements.

Method used

By determining the data attribute information of network traffic data, the category is determined based on the data attribute information, and a matching processing strategy is selected from the target database. Different Internet security protocol processing strategies are applied, including encryption or authentication processing, to achieve fine-grained encryption.

Benefits of technology

It enables targeted protection based on data sensitivity and risk level, improving the flexibility and efficiency of security management and reducing unnecessary performance overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728275B_ABST
    Figure CN119728275B_ABST
Patent Text Reader

Abstract

This application discloses a method, computer device, and storage medium for processing network traffic data. The processing method includes: obtaining network traffic data to be processed; determining data attribute information of the network traffic data; determining the category of the network traffic data based on the data attribute information; determining a target processing strategy matching the category from multiple processing strategies in a target database; and processing the network traffic data according to the target processing strategy to obtain target network traffic data. This allows for the application of different processing strategies to different types of traffic, thereby providing corresponding protection based on the sensitivity and risk level of the data. This fine-grained encryption method is more targeted than traditional global encryption, increasing the flexibility of policy management while more effectively protecting sensitive data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a method for processing network traffic data, a computer device, and a storage medium. Background Technology

[0002] With the increasing demand for network security, IPsec (Internet Protocol Security) has been widely used as a network security protocol to provide secure IP communication.

[0003] Currently, IPsec implementations are typically based on fixed security policies that rely solely on static traffic selection criteria (such as source IP, destination IP, and protocol type), resulting in all traffic being processed in the same way. This coarse-grained control approach cannot cope with complex network environments and application scenarios, potentially leading to unnecessary performance overhead or failure to meet specific security requirements. Summary of the Invention

[0004] This application provides a method for processing network traffic data, a computer device, and a storage medium, which apply different processing strategies to different types of traffic in order to perform more accurate security management.

[0005] A first aspect provides a method for processing network traffic data, comprising: obtaining network traffic data to be processed; determining data attribute information of the network traffic data, and determining the category of the network traffic data based on the data attribute information, wherein the data attribute information includes at least two of IP address, port number, application type, user identity, and time period; determining a target processing strategy matching the category from multiple processing strategies in a target database, wherein each processing strategy is based on an Internet security protocol, and the processing strategy includes whether to perform cryptographic operations and the cryptographic operation strategy used when cryptographic operations are performed; and processing the network traffic data according to the target processing strategy to obtain target network traffic data.

[0006] In a second aspect, a computer device is provided, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the network traffic data processing method as described in the first aspect.

[0007] Thirdly, a computer-readable storage medium is provided having a computer program / instructions stored thereon, which, when executed by a processor, implement the steps of the network traffic data processing method as described in the first aspect.

[0008] Fourthly, a computer program product is provided, including a computer program / instructions that, when executed by a processor, implement the steps of the network traffic data processing method as described in the first aspect.

[0009] By applying the above technical solutions, network traffic data to be processed is obtained; the data attribute information of the network traffic data is determined, and the category of the network traffic data is determined based on the data attribute information; a target processing strategy matching the category is selected from multiple processing strategies in the target database; and the network traffic data is processed according to the target processing strategy to obtain the target network traffic data. This allows for the application of different processing strategies to different types of traffic, thus providing corresponding protection based on the sensitivity and risk level of the data. This fine-grained encryption method is more targeted than traditional global encryption, increasing the flexibility of policy management while more effectively protecting sensitive data. Attached Figure Description

[0010] To more clearly illustrate the technical solutions of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 The flowchart of the network traffic data processing method in the embodiments of this application Figure 1 ;

[0012] Figure 2 The flowchart of the network traffic data processing method in the embodiments of this application Figure 2 ;

[0013] Figure 3 The flowchart of the network traffic data processing method in the embodiments of this application Figure 3 ;

[0014] Figure 4 The flowchart of the network traffic data processing method in the embodiments of this application Figure 4 ;

[0015] Figure 5 The flowchart of the network traffic data processing method in the embodiments of this application Figure 5 ;

[0016] Figure 6 This is a schematic diagram of the network traffic data processing system according to an embodiment of this application;

[0017] Figure 7 This is a structural block diagram of a computer device according to an embodiment of this application. Detailed Implementation

[0018] Various embodiments and features of this application are described herein with reference to the accompanying drawings.

[0019] It should be understood that various modifications can be made to the embodiments described herein. Therefore, the above description should not be considered as limiting, but merely as an example of embodiments. Other modifications within the scope and spirit of this application will be apparent to those skilled in the art.

[0020] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments of the present application and, together with the general description of the present application given above and the detailed description of the embodiments given below, serve to explain the principles of the present application.

[0021] These and other features of this application will become apparent from the following description of preferred forms of embodiments given as non-limiting examples, with reference to the accompanying drawings.

[0022] It should also be understood that although this application has been described with reference to some specific examples, those skilled in the art can certainly implement many other equivalent forms of this application.

[0023] The above and other aspects, features and advantages of this application will become more apparent when taken in conjunction with the accompanying drawings and in view of the following detailed description.

[0024] Specific embodiments of this application are described thereafter with reference to the accompanying drawings; however, it should be understood that the claimed embodiments are merely examples of this application, which can be implemented in various ways. Well-known and / or repeated functions and structures are not described in detail to avoid unnecessary or redundant details that could obscure the application. Therefore, the specific structural and functional details claimed herein are not intended to be limiting, but merely serve as the basis and representative basis for the claims to teach those skilled in the art to use this application in a variety of substantially any suitable detailed structures.

[0025] This specification may use the phrases “in one embodiment,” “in another embodiment,” “in yet another embodiment,” or “in other embodiments,” all of which may refer to one or more of the same or different embodiments according to this application.

[0026] This application discloses a method for processing network traffic data, which involves obtaining network traffic data to be processed; determining the data attribute information of the network traffic data; determining the category of the network traffic data based on the data attribute information; determining a target processing strategy matching the category from multiple processing strategies in a target database; and processing the network traffic data according to the target processing strategy to obtain target network traffic data. This allows for the application of different processing strategies to different types of traffic, thereby providing corresponding protection based on the sensitivity and risk level of the data. This fine-grained encryption method is more targeted than traditional global encryption, increasing the flexibility of policy management while more effectively protecting sensitive data.

[0027] like Figure 1 As shown, the method for processing this network traffic data includes the following steps:

[0028] Step S101: Obtain the network traffic data to be processed.

[0029] In this embodiment, the network traffic data to be processed can be obtained based on user access requests, or it can be traffic data sent by other servers or applications. Specifically, network traffic data can be obtained by deploying traffic monitoring tools, such as network probes, IDS (Intrusion Detection System) / IPS (Intrusion Prevention System).

[0030] In some embodiments of this application, after obtaining the network traffic data to be processed, the method further includes: preprocessing the network traffic data to ensure its accuracy. The preprocessing may include one or more of removing outliers, filling in missing values, and normalization.

[0031] Step S102: Determine the data attribute information of the network traffic data, and determine the category of the network traffic data based on the data attribute information. The data attribute information includes at least two of the following: IP address, port number, application type, user identity, and time period.

[0032] In this embodiment, the network traffic data carries data attribute information, which includes at least two of the following: IP address, port number, application type, user identity, and time period. Multiple types of network traffic data are pre-defined, with different types corresponding to different data attribute information. The category of the network traffic data is determined based on the data attribute information.

[0033] For example, a time period can be the time frame during which network traffic data is acquired. Data attribute information can be determined based on the user's identity and the time period. Different users can only access network traffic data within their corresponding time periods, resulting in different categories of network traffic data depending on the user's identity and the time period. Alternatively, data attribute information can be determined based on application type, port number, and time period. Different types of applications can only transmit network traffic data using their corresponding port numbers and time periods, again resulting in different categories of network traffic data depending on the application type, port number, and time period.

[0034] Step S103: Determine the target processing strategy that matches the category from multiple processing strategies in the target database. Each processing strategy is based on an Internet security protocol. The processing strategy includes whether to perform cryptographic operations and the cryptographic operation strategy used when cryptographic operations are performed.

[0035] In this embodiment, the target database stores multiple processing strategies based on the Internet security protocol IPsec. Each processing strategy includes whether to perform cryptographic operations, and if so, the cryptographic operation strategy used. This cryptographic operation strategy is implemented based on a corresponding encryption algorithm (such as AES, 3DES, etc.) and can characterize the encryption strength. For example, if the first processing strategy and the second processing strategy involve performing cryptographic operations, the first processing strategy uses the first cryptographic operation strategy, and the second processing strategy uses the second cryptographic operation strategy. The encryption strengths of the first and second cryptographic operation strategies are different.

[0036] There is a correspondence between each processing strategy and each type of network traffic data. After determining the type of network traffic data, the target database is queried based on the type, and the processing strategy that matches the type is determined as the target processing strategy. It can be understood that the target processing strategy also includes whether to perform cryptographic operations, and if so, the cryptographic operation strategy used.

[0037] Step S104: Process the network traffic data according to the target processing strategy to obtain target network traffic data.

[0038] In this embodiment, network traffic data is processed according to the target processing strategy to make the network traffic data meet the security requirements corresponding to the target processing strategy, thereby obtaining the target network traffic data, which can then be processed or forwarded.

[0039] In some embodiments of this application, network traffic data can be processed at the network layer or application layer according to a target processing strategy, so as to realize the processing of network traffic data at the firewall or router.

[0040] In some embodiments of this application, network traffic data is in plaintext, and target network traffic data is in ciphertext.

[0041] The network traffic data processing method of this application embodiment obtains network traffic data to be processed; determines the data attribute information of the network traffic data, and determines the category of the network traffic data based on the data attribute information. The data attribute information includes at least two of IP address, port number, application type, user identity, and time period; determines a target processing strategy matching the category from multiple processing strategies in a target database. Each processing strategy is based on Internet security protocols and includes whether to perform cryptographic operations and the cryptographic operation strategy used if cryptographic operations are performed; processes the network traffic data according to the target processing strategy to obtain target network traffic data. This allows for the application of different processing strategies to different types of traffic, thereby providing corresponding protection based on the sensitivity and risk level of the data. This fine-grained encryption method is more targeted than traditional global encryption, increasing the flexibility of policy management while more effectively protecting sensitive data.

[0042] In some embodiments of this application, the network traffic data is processed according to the target processing strategy to obtain target network traffic data, such as... Figure 2 As shown, it includes the following steps:

[0043] Step S1041: If the target processing strategy is to perform cryptographic operations, the network traffic data is processed using the cryptographic operation strategy in the target processing strategy to obtain the target network traffic data. The cryptographic operation process includes encryption processing or authentication processing.

[0044] In this embodiment, cryptographic processing includes encryption or authentication. If the target processing strategy is cryptographic processing, the cryptographic strategy within the target processing strategy is determined, and the network traffic data is encrypted or authenticated using the cryptographic strategy to obtain the target network traffic data. For example, if encryption is required based on the type of network traffic data and a strong encryption strength is needed, the cryptographic strategy in the target processing strategy will have a strong encryption strength to ensure security. If encryption is required based on the type of network traffic data and a lower encryption strength is needed, the cryptographic strategy in the target processing strategy will have a lower encryption strength to improve encryption efficiency. If authentication is required based on the type of network traffic data and a lower encryption strength is needed, the cryptographic strategy in the target processing strategy will have a lower encryption strength (e.g., using a simple authentication algorithm or a single authentication method) to improve authentication efficiency.

[0045] Step S1042: When the target processing strategy is not to perform cryptographic operations, the network traffic data is determined as the target network traffic data.

[0046] In this embodiment, if the target processing strategy is not to perform cryptographic operations, it means that there is no need to process the network traffic data, and the network traffic data is directly identified as the target network traffic data.

[0047] By performing cryptographic operations according to the corresponding strategy when the target processing strategy is to perform cryptographic operations, and not processing network traffic data when the target processing strategy is not to perform cryptographic operations, the system can accurately adjust the processing strategy based on the type of network traffic data, rationally use system resources, ensure that it does not have an excessive impact on network performance, and improve the flexibility and accuracy of security management.

[0048] In some embodiments of this application, after obtaining the target network traffic data, such as Figure 3 As shown, it also includes the following steps:

[0049] Step S105: Obtain network environment data, which includes at least one of network traffic, network status, and security events.

[0050] In this embodiment, network environment data includes at least one of network traffic, network status, and security events. Network traffic can be the size and type of network traffic, network status can be the network bandwidth, latency, throughput, packet loss rate, round-trip time (RTT), channel utilization, etc., and security events can be, for example, DoS attacks, DDoS attacks, phishing attacks, password attacks, SQL injection attacks, DNS spoofing, brute-force attacks, etc.

[0051] Step S106: Evaluate the network environment data using target evaluation rules to determine the environmental attribute information of the network environment data. The environmental attribute information includes at least one of security threat level and network load.

[0052] In this embodiment, the target evaluation rule can be a rule in the threat intelligence platform or a custom evaluation rule. The target evaluation rule is used to evaluate network environment data and determine the environmental attribute information of the network environment data. The environmental attribute information can be the security threat level, the network load, or both the security threat level and the network load.

[0053] Step S107: If the environmental attribute information does not match the target processing strategy, update the target processing strategy according to the environmental attribute information.

[0054] In this embodiment, it is determined whether the environmental attribute information matches the target processing strategy. If they do not match, the target processing strategy is updated based on the environmental attribute information. For example, if the security threat level increases, causing the current target processing strategy to fail to meet the security requirements corresponding to the security threat level, it is determined that the environmental attribute information and the target processing strategy do not match. In this case, the cryptographic operation strategy in the target processing strategy can be replaced with a cryptographic operation strategy with higher encryption strength to update the target processing strategy. Alternatively, if the network load increases and the security threat level decreases, but the current target processing strategy using a cryptographic operation strategy with higher encryption strength would cause the network load to increase further, it is determined that the environmental attribute information and the target processing strategy do not match. In this case, the cryptographic operation strategy in the target processing strategy can be replaced with a cryptographic operation strategy with lower encryption strength to update the target processing strategy and reduce the network load.

[0055] Step S108: Process the new network traffic data according to the updated target processing strategy.

[0056] The new network traffic data may be encrypted or authenticated according to the updated target processing policy, or no processing may be performed on the new network traffic data, so that the processed new network traffic data meets the security requirements that match the updated target processing policy.

[0057] When environmental attribute information and target processing strategy do not match, the target processing strategy is updated by updating the environmental attribute information of network environment data. This enables automatic and dynamic adjustment of the target processing strategy according to different network environments, which can avoid unnecessary encryption overhead or potential security risks and improve security management efficiency.

[0058] In some embodiments of this application, updating the target processing strategy based on the environmental attribute information includes one of the following:

[0059] The cryptographic operation strategy in the target processing strategy is updated according to the environmental attribute information to change the encryption strength corresponding to the cryptographic operation strategy;

[0060] Based on the environmental attribute information, the target processing strategy is updated from not performing cryptographic operations to performing cryptographic operations, and the cryptographic operation strategy in the updated target processing strategy is determined.

[0061] Based on the environmental attribute information, the target processing strategy is updated from performing cryptographic operations to not performing cryptographic operations.

[0062] In this embodiment, the cryptographic operation strategy can be updated in various ways depending on different situations. The cryptographic operation strategy in the target processing strategy can be updated based on environmental attribute information to change the encryption strength corresponding to the cryptographic operation strategy. For example, if the security threat level increases, the encryption strength corresponding to the cryptographic operation strategy is increased; if the security threat level decreases, the encryption strength corresponding to the cryptographic operation strategy is decreased, thereby reducing unnecessary cryptographic operation overhead and improving data processing efficiency.

[0063] It is also possible to update the target processing policy from not performing cryptographic operations to performing cryptographic operations based on environmental attribute information, and determine the cryptographic operation policy in the updated target processing policy. For example, if the current target processing policy is not performing cryptographic security operations, after the security threat level increases, the target processing policy will be updated from not performing cryptographic operations to performing cryptographic operations, and the cryptographic operation policy corresponding to the current security threat level will be determined to meet the security requirements under the current security threat level.

[0064] It can also update the target processing strategy from performing cryptographic operations to not performing cryptographic operations based on environmental attribute information. For example, if the current target processing strategy is to perform cryptographic security operations, after the network load increases and the security threat level decreases, the target processing strategy can be updated to not perform cryptographic operations to reduce unnecessary cryptographic operation overhead, reduce network load, and improve the processing efficiency of other tasks.

[0065] In some embodiments of this application, after obtaining the target network traffic data, such as Figure 4 As shown, it also includes the following steps:

[0066] Step S109: In response to the update command issued by the user, update the target processing strategy according to the update command.

[0067] In this embodiment, in addition to automatically updating the target processing strategy based on environmental attribute information, update instructions for updating the target processing strategy issued by the user can also be obtained from the human-computer interaction interface or user terminal. The target processing strategy can be updated according to the update instructions. For example, the cryptographic operation strategy in the target processing strategy can be updated according to the update instructions to change the encryption strength corresponding to the cryptographic operation strategy; the target processing strategy can also be updated from not performing cryptographic operation processing to performing cryptographic operation processing according to the update instructions, and the cryptographic operation strategy in the updated target processing strategy can be determined; the target processing strategy can also be updated from performing cryptographic operation processing to not performing cryptographic operation processing according to the update instructions.

[0068] Step S110: Process the new network traffic data according to the updated target processing strategy.

[0069] The new network traffic data is processed according to the updated target processing policy to ensure that the processed new network traffic data meets the security requirements of the updated target processing policy.

[0070] By updating the target processing strategy according to the update command, the processing strategy can be updated according to the user's needs, thus improving the user experience.

[0071] In some embodiments of this application, such as Figure 5 As shown, it also includes the following steps:

[0072] Step S111: In response to receiving a configuration instruction for the target database, a configuration operation is performed on the target database. The configuration operation includes at least one of adding a processing strategy, deleting a processing strategy, updating a processing strategy, updating the data category associated with the processing strategy, and updating the priority of the processing strategy.

[0073] In this embodiment, a graphical user interface (GUI) and a command-line interface (CLI) can be provided, allowing administrators to define and configure policies. Configuration commands for the target database can be issued by the user. Upon receiving a configuration command, at least one of the following actions can be performed: adding a processing policy, deleting a processing policy, updating a processing policy, updating the data category associated with a processing policy, and updating the priority of a processing policy. When performing configuration operations, users can use at least two of the following: IP address, port number, application type, user identity, and time period.

[0074] Step S112: Send the change data corresponding to the configuration operation in the target database to the target peer device.

[0075] In this embodiment, after the configuration operation is completed, the changed data corresponding to the configuration operation in the target database is sent to the target peer device, thereby ensuring that the target peer device can correctly decrypt the received network traffic data.

[0076] By configuring the target database using configuration commands, users can configure the processing strategies in the target database as needed, improving the user experience. Furthermore, by sending the changed data in the target database corresponding to the configuration operation to the target peer device, the target peer device can correctly decrypt the received network traffic data, thus improving the reliability of security management.

[0077] In some embodiments of this application, the method further includes: responding to receiving a query instruction for the target database, querying the processing instructions in the target database according to the query instruction, and returning the query results, thereby satisfying the user's query needs for processing strategies and improving the user experience.

[0078] In some embodiments of this application, determining the category of the network traffic data based on the data attribute information includes:

[0079] The network traffic data is classified using deep packet inspection technology or machine learning algorithms to determine the category.

[0080] Following this embodiment, deep packet inspection technology or machine learning algorithms can be used to classify the network traffic data, thereby achieving efficient determination of the category of network traffic data.

[0081] This application also proposes a method for processing network traffic data, such as... Figure 6 As shown, applied to a system including a policy management module, a dynamic analysis module, an encryption control module, and a policy update module, this processing method includes:

[0082] The dynamic analysis module is used to obtain network traffic data to be processed.

[0083] The dynamic analysis module determines the data attribute information of the network traffic data, determines the category of the network traffic data based on the data attribute information, and provides the category to the encryption control module. The data attribute information includes at least two of the following: IP address, port number, application type, user identity, and time period.

[0084] Using the encryption control module, a target processing strategy matching the category is determined from multiple processing strategies in the target database of the policy management module. Each processing strategy is based on an Internet security protocol, and the processing strategy includes whether to perform cryptographic operations and the cryptographic operation strategy adopted when cryptographic operations are performed.

[0085] The network traffic data is processed using the encryption control module according to the target processing strategy to obtain the target network traffic data.

[0086] In some embodiments of this application, an encryption control module is used to process the network traffic data according to the target processing strategy to obtain target network traffic data, including:

[0087] When the target processing strategy is to perform cryptographic operations, the encryption control module is used to perform cryptographic operations on the network traffic data based on the cryptographic operation strategy in the target processing strategy to obtain the target network traffic data. The cryptographic operation process includes encryption processing or authentication processing.

[0088] When the target processing strategy is to not perform cryptographic operations, the encryption control module is used to identify the network traffic data as the target network traffic data.

[0089] In some embodiments of this application, after obtaining the target network traffic data, the method further includes:

[0090] Network environment data is obtained using a dynamic analysis module, and the network environment data includes at least one of network traffic, network status, and security events.

[0091] The dynamic analysis module evaluates the network environment data according to the target evaluation rules, determines the environmental attribute information of the network environment data, and outputs it to the policy update module. The environmental attribute information includes at least one of security threat level and network load.

[0092] If the environmental attribute information does not match the target processing strategy, the strategy update module is used to update the target processing strategy according to the environmental attribute information and push it to the strategy management module.

[0093] The encrypted control module obtains the updated target processing policy from the policy management module and processes the new network traffic data according to the updated target processing policy.

[0094] In some embodiments of this application, the policy update module updates the target processing policy based on the environmental attribute information and pushes it to the policy management module, including one of the following:

[0095] The policy update module is used to update the cryptographic operation policy in the target processing policy according to the environmental attribute information, so as to change the encryption strength corresponding to the cryptographic operation policy.

[0096] Using the policy update module, the target processing policy is updated from not performing cryptographic operations to performing cryptographic operations based on the environmental attribute information, and the cryptographic operation policy in the updated target processing policy is determined.

[0097] Using the policy update module, the target processing policy is updated from performing cryptographic operations to not performing cryptographic operations based on the environmental attribute information.

[0098] In some embodiments of this application, after obtaining the target network traffic data, the method further includes:

[0099] In response to an update command issued by the user, the policy update module updates the target processing policy according to the update command and outputs it to the encryption control module;

[0100] The encryption control module processes new network traffic data according to the updated target processing strategy.

[0101] In some embodiments of this application, after obtaining the target network traffic data, the method further includes: using the policy update module to collect feedback from the encryption control module and the dynamic analysis module, evaluating the policy effect, generating optimization suggestions, and using a log management tool to perform data analysis.

[0102] In some embodiments of this application, it also includes:

[0103] In response to receiving a configuration instruction for the target database, the policy management module performs configuration operations on the target database. The configuration operations include at least one of adding a processing policy, deleting a processing policy, updating a processing policy, updating the data category associated with the processing policy, and updating the priority of the processing policy.

[0104] Using the policy management module, the changed data corresponding to the configuration operation in the target database is sent to the target peer device.

[0105] In some embodiments of this application, determining the category of the network traffic data based on the data attribute information includes:

[0106] The network traffic data is classified using a dynamic analysis module based on deep packet inspection technology or machine learning algorithms to determine the category.

[0107] To further illustrate the technical concept of this application, the technical solution will now be explained in conjunction with specific application scenarios.

[0108] Scenario 1: An enterprise allows employees to remotely access the company's internal network via VPN, involving the transmission of sensitive business data. Detailed applications are as follows:

[0109] Policy Configuration: Enterprises define fine-grained encryption policies, adjusting encryption levels based on employee access permissions and data sensitivity. For example, data transmission requires a higher encryption level when finance department employees access the system remotely.

[0110] Traffic monitoring: The dynamic analysis module monitors the traffic of remote workers in real time and analyzes whether there is any abnormal activity, such as unauthorized access attempts or data leaks.

[0111] Dynamic encryption: If the dynamic analysis module detects abnormal traffic or unauthorized access, the encryption control module will automatically increase the encryption strength of the relevant traffic to protect data security.

[0112] Policy Adjustment: The policy update module regularly optimizes encryption policies based on real-time analysis data and changes in the remote work environment, and pushes the updates to the policy management module to ensure that all policies are centrally managed.

[0113] Scenario 2: An organization processes highly confidential communication data and internal documents, and needs to prevent information leakage and unauthorized access. Detailed application is as follows:

[0114] Encryption Strategy: Set fine-grained encryption strategies for different types of files and communications. For example, confidential files use the strongest encryption algorithm, while general internal communications use medium-strength encryption.

[0115] Security Monitoring: The dynamic analysis module monitors internal network traffic to analyze for suspicious access behavior or data leakage risks. If any anomalies are detected, the encryption control module is immediately notified.

[0116] Encryption Adjustment: The encryption control module automatically adjusts the encryption strategy based on monitoring results to strengthen the protection of classified communications.

[0117] Policy Update: The policy update module combines analytical data and security incidents to regularly adjust encryption policies, ensuring continuous protection and compliance.

[0118] By applying the above technical solutions, the following technical effects are achieved:

[0119] 1. Enhance data security

[0120] By applying different levels of encryption to different types of traffic, the system can provide corresponding protection based on the sensitivity and risk level of the data. This fine-grained encryption method is more targeted than traditional global encryption and can more effectively protect sensitive data.

[0121] 2. Real-time threat detection and response

[0122] Real-time monitoring and analysis of network traffic can quickly identify abnormal behavior or potential security threats. For example, abnormal traffic patterns or suspicious access attempts can be detected promptly, triggering appropriate security responses.

[0123] 3. Improve network performance and efficiency

[0124] Different encryption strengths are applied based on the type and requirements of traffic. When the local configuration algorithm changes, the policy management module synchronizes with the peer device in real time, enabling the system to optimize network performance while ensuring security. For example, lighter encryption can be used for non-sensitive data, and the policy can be synchronized with the peer device to reduce the consumption of system resources.

[0125] 4. Flexible strategy management

[0126] It supports applying different security policies to different types of traffic, enhancing the flexibility of policy management. Policies can be customized based on departments, user roles, or data types, thereby improving the precision of security management.

[0127] This application also proposes a network traffic data processing apparatus, comprising: a first obtaining unit for obtaining network traffic data to be processed; a first determining unit for determining data attribute information of the network traffic data and determining the category of the network traffic data based on the data attribute information, wherein the data attribute information includes at least two of IP address, port number, application type, user identity, and time period; a second determining unit for determining a target processing strategy matching the category from multiple processing strategies in a target database, wherein each processing strategy is based on an Internet security protocol and the processing strategy includes whether to perform cryptographic operations and the cryptographic operation strategy adopted when cryptographic operations are performed; and a second obtaining unit for processing the network traffic data according to the target processing strategy to obtain target network traffic data.

[0128] The network traffic data processing apparatus of this application embodiment obtains network traffic data to be processed through a first obtaining unit; determines data attribute information of the network traffic data through a first determining unit, and determines the category of the network traffic data based on the data attribute information; determines a target processing strategy matching the category from multiple processing strategies in a target database through a second determining unit; and processes the network traffic data according to the target processing strategy through a second obtaining unit to obtain target network traffic data. This allows for the application of different processing strategies to different types of traffic, thereby providing corresponding protection based on the sensitivity and risk level of the data. This fine-grained encryption method is more targeted than traditional global encryption, increasing the flexibility of policy management while more effectively protecting sensitive data.

[0129] In a specific application scenario, the second obtaining unit is specifically used to: when the target processing strategy is to perform cryptographic operations, use the cryptographic operation strategy in the target processing strategy to perform cryptographic operations on the network traffic data to obtain the target network traffic data, wherein the cryptographic operation includes encryption processing or authentication processing; and when the target processing strategy is not to perform cryptographic operations, determine the network traffic data as the target network traffic data.

[0130] In specific application scenarios, an update unit is also included, which is used to: obtain network environment data, the network environment data including at least one of network traffic, network status, and security events; evaluate the network environment data using target evaluation rules to determine the environmental attribute information of the network environment data, the environmental attribute information including at least one of security threat level and network load; update the target processing policy according to the environmental attribute information if the environmental attribute information does not match the target processing policy; and process the new network traffic data according to the updated target processing policy.

[0131] In specific application scenarios, the update unit is specifically used to perform one of the following: update the cryptographic operation strategy in the target processing strategy according to the environmental attribute information to change the encryption strength corresponding to the cryptographic operation strategy; update the target processing strategy from not performing cryptographic operation processing to performing cryptographic operation processing according to the environmental attribute information, and determine the cryptographic operation strategy in the updated target processing strategy; update the target processing strategy from performing cryptographic operation processing to not performing cryptographic operation processing according to the environmental attribute information.

[0132] In specific application scenarios, the update unit is also used to: respond to an update instruction issued by the user, update the target processing strategy according to the update instruction; and process new network traffic data according to the updated target processing strategy.

[0133] In specific application scenarios, a configuration unit is also included, which is used to: in response to receiving a configuration instruction for the target database, perform configuration operations on the target database, wherein the configuration operations include at least one of adding a processing strategy, deleting a processing strategy, updating a processing strategy, updating the data category associated with the processing strategy, and updating the priority of the processing strategy; and send the changed data in the target database corresponding to the configuration operations to the target peer device.

[0134] In a specific application scenario, the first determining unit is specifically used to: classify the network traffic data using deep packet inspection technology or machine learning algorithms to determine the category.

[0135] This application also provides a computer device, such as... Figure 7 As shown, it includes a processor and a memory, wherein the memory stores an executable program, and the processor executes the steps of the network traffic data processing method described in various embodiments of this application.

[0136] The computer device in this application embodiment can be a terminal or other devices besides a terminal. For example, the computer device can be a mobile phone, tablet computer, laptop computer, handheld computer, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc. It can also be a server, network attached storage (NAS), personal computer (PC), television (TV), ATM, or self-service machine, etc. The embodiments disclosed in this disclosure do not impose specific limitations.

[0137] The memory may include RAM (Random Access Memory) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0138] The processors mentioned above can be general-purpose processors, including CPUs, NPs (Network Processors), etc.; they can also be DSPs (Digital Signal Processors), ASICs (Application Specific Integrated Circuits), FPGAs (Field Programmable Gate Arrays), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0139] In another embodiment provided in this application, a computer-readable storage medium is also provided, on which a computer program / instruction is stored, which, when executed by a processor, implements the steps of the network traffic data processing method described in various embodiments of this application.

[0140] In another embodiment provided in this application, a computer program product is also provided, including a computer program / instructions that, when executed by a processor, implement the steps of the network traffic data processing method described in various embodiments of this application.

[0141] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0142] The above embodiments are merely exemplary embodiments of this application and are not intended to limit this application. The scope of protection of this application is defined by the claims. Those skilled in the art can make various modifications or equivalent substitutions to this application within its substance and scope of protection, and such modifications or equivalent substitutions should also be considered to fall within the scope of protection of this application.

Claims

1. A method for processing network traffic data, characterized in that, include: Obtain network traffic data to be processed; Determine the data attribute information of the network traffic data, and determine the category of the network traffic data based on the data attribute information. The data attribute information includes at least two of the following: IP address, port number, application type, user identity, and time period. A target processing strategy matching the category is determined from multiple processing strategies in the target database. Each processing strategy is based on an Internet security protocol. The processing strategy includes whether to perform cryptographic operations and the cryptographic operation strategy adopted when cryptographic operations are performed. The network traffic data is processed according to the target processing strategy to obtain target network traffic data; After obtaining the target network traffic data, the process also includes: Obtain network environment data, wherein the network environment data includes at least one of network traffic, network status, and security events; The network environment data is evaluated using target evaluation rules to determine the environmental attribute information of the network environment data, which includes at least one of security threat level and network load. If the environmental attribute information does not match the target processing strategy, the target processing strategy is updated according to the environmental attribute information. The new network traffic data is processed according to the updated target processing strategy.

2. The method for processing network traffic data as described in claim 1, characterized in that, The network traffic data is processed according to the target processing strategy to obtain target network traffic data, including: When the target processing strategy is to perform cryptographic operations, the network traffic data is processed using the cryptographic operation strategy in the target processing strategy to obtain the target network traffic data. The cryptographic operation process includes encryption processing or authentication processing. When the target processing strategy is to not perform cryptographic operations, the network traffic data is identified as the target network traffic data.

3. The method for processing network traffic data as described in claim 1, characterized in that, The target processing strategy is updated based on the environmental attribute information, including one of the following: The cryptographic operation strategy in the target processing strategy is updated according to the environmental attribute information to change the encryption strength corresponding to the cryptographic operation strategy; Based on the environmental attribute information, the target processing strategy is updated from not performing cryptographic operations to performing cryptographic operations, and the cryptographic operation strategy in the updated target processing strategy is determined. Based on the environmental attribute information, the target processing strategy is updated from performing cryptographic operations to not performing cryptographic operations.

4. The method for processing network traffic data as described in claim 1, characterized in that, After obtaining the target network traffic data, the process also includes: In response to an update command issued by the user, the target processing strategy is updated according to the update command; The new network traffic data is processed according to the updated target processing strategy.

5. The method for processing network traffic data as described in claim 1, characterized in that, Also includes: In response to receiving a configuration instruction for the target database, a configuration operation is performed on the target database, the configuration operation including at least one of adding a processing strategy, deleting a processing strategy, updating a processing strategy, updating the data category associated with the processing strategy, and updating the priority of the processing strategy; The changed data corresponding to the configuration operation in the target database is sent to the target peer device.

6. The method for processing network traffic data as described in claim 1, characterized in that, Determining the category of the network traffic data based on the data attribute information includes: The network traffic data is classified using deep packet inspection technology or machine learning algorithms to determine the category.

7. A computer device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the network traffic data processing method as described in any one of claims 1-6.

8. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instruction is executed by the processor, it implements the steps of the method for processing network traffic data as described in any one of claims 1-6.

9. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the steps of the method for processing network traffic data as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Data processing method, device and equipment

    CN117131211A

  • Encrypted traffic vulnerability scanning detection method and device, electronic equipment and storage medium

    CN118118253A