A computer network communication security monitoring method and system

Through the Grubbs detection algorithm, traffic data, VPN connections and data packets are detected in real time, communication assignments are generated and communication quality is analyzed, and the security problem caused by single-dimensional monitoring in the existing technology is solved, and more comprehensive communication security monitoring is achieved.

CN119834994BActive Publication Date: 2025-07-22成都思拓知识产权服务有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410221132.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-28
Publication Date
2025-07-22
Estimated Expiration
2044-02-28

AI Technical Summary

Technical Problem

The existing monitoring methods mainly focus on single-dimensional monitoring, resulting in insufficient perception of comprehensive attacks and the inability to fully guarantee communication security.

Method used

The Grubbs detection algorithm is used to detect traffic data, VPN connections and data packets in real time, generate communication assignments through weighted calculations, and generate control strategies based on gradient anomaly thresholds, and analyze communication quality in combination with polynomial algorithms.

Benefits of technology

It improves the comprehensiveness and effectiveness of communication security monitoring, and can conduct secondary analysis without abnormal conditions, further improving communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119834994B_ABST
    Figure CN119834994B_ABST
Patent Text Reader

Abstract

The present invention discloses a computer network communication security monitoring method and system, which relates to the technical field of communication monitoring. During the communication process, the Grubbs detection algorithm is combined to detect traffic data, VPN connections, and data packets in real time, and analyze whether there are outliers in the traffic data, VPN connections, and data packets. When no communication anomaly is detected, the G values obtained by calculating the traffic data, VPN connections, and data packets through the Grubbs detection algorithm are acquired, and multiple G values are weighted and calculated to generate a communication assignment. Based on the comparison result between the communication assignment and the gradient anomaly threshold, corresponding control strategies are generated. After the communication ends, the communication quality of this time is analyzed. This monitoring method can comprehensively analyze the G values of traffic data, VPN connections, and data packets when no communication anomaly is detected, and perform a secondary analysis on communication security, further improving the security of communication monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of communication monitoring, and particularly relates to a computer network communication security monitoring method and system. Background Art

[0002] With the development of information technology, a large amount of sensitive information is transmitted through computer networks, such as personal privacy, financial data, etc. In order to ensure the security of this information, communication security monitoring needs to adopt technologies such as encryption and authentication to prevent unauthorized access and data leakage.

[0003] The prior art has the following deficiencies:

[0004] Existing monitoring methods mainly focus on monitoring specific dimensions, such as analysis of traffic data, VPN connections, or data packets. Monitoring a single dimension may lead to the neglect of comprehensive problems because attackers may use multiple means to attack. The lack of comprehensive analysis may cause the system to have insufficient awareness of various threats, thus unable to ensure the security of communication. Summary of the Invention

[0005] The purpose of the present invention is to provide a computer network communication security monitoring method and system to solve the deficiencies in the background art.

[0006] To achieve the above purpose, the present invention provides the following technical solution: A computer network communication security monitoring method, the monitoring method includes the following steps:

[0007] Before communication, the monitoring system detects whether there is abnormal traffic in the computer network based on the algorithm of time series pattern recognition, and identifies whether there are outliers in the traffic data through the Grubbs detection algorithm. If there is no abnormal traffic and no outliers in the traffic data, the monitoring system prompts that the computer network supports communication;

[0008] During communication, monitor the VPN connection based on the protocol analysis algorithm, identify whether there are potential abnormalities in the VPN communication, and detect whether there are outliers in the VPN connection mode through the Grubbs detection algorithm;

[0009] Real-time filter and deeply detect the data packets incoming and outgoing from the communication, identify whether there are threats in the data packets, and detect whether there are outliers in the data packets through the Grubbs detection algorithm;

[0010] If communication abnormalities are detected, the monitoring system directly controls the communication to be interrupted. If no communication abnormalities are detected, obtain the G values calculated by the Grubbs detection algorithm for the traffic data, VPN connection, and data packets, and perform weighted calculation on multiple G values to generate a communication assignment. Based on the comparison result between the communication assignment and the gradient anomaly threshold, generate corresponding control strategies;

[0011] After the communication ends, after calculating the average communication assignment and the communication interruption frequency during the communication process through the polynomial algorithm, analyze the communication quality of this time, and send the analysis results to the administrator and store them in the database for subsequent analysis.

[0012] Preferably, the communication anomalies include abnormal network traffic, potential anomalies in VPN communication, packet threats, or the existence of outliers.

[0013] Preferably, the Grubbs detection algorithm is used to identify whether there are outliers in the traffic data, including the following steps:

[0014] Obtain a number of data points in the traffic data, and calculate the X value of each data point. The expression is: In the formula, X i represents the X value of the i-th data point, and x i represents the traffic value of the i-th data point, and x avg represents the average traffic, and a represents the standard deviation of the traffic data;

[0015] Calculate the Grubbs statistic (G value) of the traffic data. The function expression is:

[0016] In the formula, N1 is the number of data points in the traffic data, X i represents the X value of the i-th data point, G1 represents the G value of the traffic data, and max(X i ) represents the maximum X value among the selected i data points;

[0017] Compare the G value of the obtained traffic data with the preset traffic dispersion threshold. If the G value of the traffic data is greater than the traffic dispersion threshold, analyze that there are outliers in the traffic data and judge that the traffic data is abnormal;

[0018] Use the Grubbs detection algorithm to detect whether there are outliers in the VPN connection mode, including the following steps:

[0019] Obtain a number of data points in the VPN connection, and calculate the Y value of each data point. The expression is: In the formula, Y i represents the Y value of the i-th data point, and y i represents the data transfer rate of the i-th data point, and y avg represents the average data transfer rate, and b represents the standard deviation of the VPN connection;

[0020] Calculate the Grubbs statistic (G value) of the VPN connection. The function expression is:

[0021] In the formula, N2 is the number of data points in the VPN connection, Yi represents the Y value of the i-th data point, G2 represents the G value of the VPN connection, and max(Y i ) represents the maximum Y value among the i data points;

[0022] Compare the obtained G value of the VPN connection with a preset VPN discrete threshold. If the G value of the VPN connection is greater than the VPN discrete threshold, analyze that there are outliers in the VPN connection and determine that the VPN connection is abnormal.

[0023] Detect whether there are outliers in the data packet through the Grubbs detection algorithm, including the following steps:

[0024] Obtain several data points in the data packet and calculate the Z value of each data point. The expression is: In the formula, Z i represents the Z value of the i-th data point, z i represents the transmission time interval of the i-th data point, z avg represents the average transmission time interval, and c represents the standard deviation of the data packet;

[0025] Calculate the Grubbs statistic (G value) of the data packet. The function expression is:

[0026] In the formula, N3 is the number of data points in the data packet, Z i represents the Z value of the i-th data point, G3 represents the G value of the data packet, and max(Z i ) represents the maximum Z value among the i data points;

[0027] Compare the obtained G value of the data packet with a preset data packet discrete threshold. If the G value of the data packet is greater than the data packet discrete threshold, analyze that there are outliers in the data packet and determine that the data packet is abnormal.

[0028] Preferably, if no communication anomaly is detected, obtain the G values of the traffic data, VPN connection, and data packet calculated through the Grubbs detection algorithm, and perform weighted calculation on multiple G values to generate a communication assignment, including the following steps:

[0029] During communication, regularly obtain the G value of the traffic data, the G value of the VPN connection, and the G value of the data packet;

[0030] The communication assignment is obtained by comprehensively weighted calculation of the G value of traffic data, the G value of VPN connection, and the G value of data packets. The expression is: tfz = ω1 * G1 + ω2 * G2 + ω3 * G3. In the formula, tfz is the communication assignment, G1, G2, and G3 are the G value of traffic data, the G value of VPN connection, and the G value of data packets respectively, ω1, ω2, and ω3 are the weight coefficients of the G value of traffic data, the G value of VPN connection, and the G value of data packets respectively, and ω1 + ω2 + ω3 = 1, ω2 > ω1 = ω3.

[0031] Preferably, a corresponding control strategy is generated based on the comparison result between the communication assignment and the gradient anomaly threshold, including the following steps:

[0032] After obtaining the communication assignment regularly, compare the communication assignment with the gradient threshold. The gradient threshold includes a first anomaly threshold and a second anomaly threshold. The first anomaly threshold is used to analyze whether there is an anomaly in the communication process, and the second anomaly threshold is used to analyze the severity of the communication anomaly;

[0033] If the communication assignment is less than the first anomaly threshold, it is analyzed that there is no anomaly in the communication process;

[0034] If the communication assignment is greater than or equal to the first anomaly threshold, it is analyzed that there is an anomaly in the communication process;

[0035] If the communication assignment is greater than or equal to the first anomaly threshold and less than the second anomaly threshold, it is analyzed that there is a minor anomaly in the communication process, indicating that the communication can continue. At this time, the monitoring system does not process the communication, sends a warning to the user, and the user can choose whether to continue the communication independently;

[0036] If the communication assignment is greater than or equal to the second anomaly threshold, it is analyzed that there is a serious anomaly in the communication process, indicating that continued communication is not supported, and the monitoring system directly disconnects the communication.

[0037] Preferably, after the communication ends, the average communication assignment and the communication interruption frequency during the communication process are calculated through a polynomial algorithm, and then the communication quality is analyzed, including the following steps:

[0038] After the communication ends, obtain the communication assignments obtained multiple times during the communication process, and calculate the average communication assignment of the multiple communication assignments;

[0039] And obtain the communication interruption frequency during the communication process through a communication monitoring tool. The average communication assignment and the communication interruption frequency are calculated through a polynomial algorithm to obtain a quality coefficient. The expression is:

[0040] Zxs = α * tfz avg + β * zdp; In the formula, Zxs is the quality coefficient, tfz avg, zdp are the average communication assignment and the communication interruption frequency respectively, α and β are the proportionality coefficients of the average communication assignment and the communication interruption frequency respectively, and both α and β are greater than 0;

[0041] Compare the quality coefficient with a preset quality threshold. If the quality coefficient is less than or equal to the quality threshold, it is analyzed that the communication quality is qualified. If the quality coefficient is greater than the quality threshold, it is analyzed that the communication quality is unqualified. Send the analysis result to the administrator and store it in the database for subsequent analysis.

[0042] Preferably, before communication, the monitoring system detects whether there is abnormal traffic in the computer network based on the algorithm of time series pattern recognition, including the following steps:

[0043] Use a network packet capture tool to capture real-time data packets from the network. The data packets include the transmitted information, the data packet size, and the transmission rate. Arrange the captured data packets in chronological order to form a time series data sequence;

[0044] Use a time window to divide the time series data into small time periods, extract features from each time window, calculate the mean and standard deviation of the data packet size within each time window to model the time series pattern, and compare the real-time traffic data with the modeled time series pattern to detect whether there are abnormal situations that do not match the normal traffic pattern.

[0045] Preferably, during communication, monitor the VPN connection based on the protocol analysis algorithm to identify whether there are potential abnormalities in the VPN communication, including the following steps:

[0046] Capture the network traffic data of the VPN communication, including the transmitted data packets, the protocol type, and the source and destination IP address information. Use a network packet capture tool or a monitoring device to capture the data packets passing through the VPN connection and perform protocol analysis on the captured VPN traffic to identify the protocol used in the communication;

[0047] Analyze the header information of the data packets to determine the protocol type used, extract the protocol features from the VPN communication, and use the known protocol specifications and feature information to establish a model of the VPN communication behavior, including the allowed protocol version, encryption algorithm, and authentication method;

[0048] During communication, analyze the real-time VPN traffic and compare it with the model of the VPN communication behavior to check whether the protocol features of the real-time VPN traffic match the established protocol behavior model and identify situations that do not match the normal behavior.

[0049] Preferably, perform real-time filtering and in-depth detection on the data packets incoming and outgoing from the communication to identify whether there are threats in the data packets, including the following steps:

[0050] Capture the incoming and outgoing data packets of the communication, obtain the detailed information of the data packets, including the source address, destination address, protocol type, and data size, and use a network packet capture tool or a firewall device to intercept the data packets passing through the network device;

[0051] Use a firewall or intrusion detection system to perform real-time filtering on the incoming and outgoing data packets according to the source address, destination address, and protocol information, and use a deep packet inspection tool to perform in-depth parsing on the data packets that pass through the real-time filtering, and further analyze the content and structure of the data packets, where the content and structure include the data payload and protocol header;

[0052] Use a malicious code scanning engine and an intrusion detection system to detect whether there are malicious features in the data packets, including malicious code and attack signatures, perform feature matching on the data packets to identify whether they contain known malicious features, analyze the behaviors in the data packets, and detect whether there are abnormal behaviors.

[0053] A computer network communication security monitoring system, including a traffic monitoring module, a judgment module, a VPN monitoring module, a data packet monitoring module, a detection module, a communication interruption module, a secondary analysis module, and a quality analysis module;

[0054] Traffic monitoring module: Before communication, detect whether there is abnormal traffic in the computer network based on the algorithm of time series pattern recognition, and identify whether there are outliers in the traffic data through the Grubbs detection algorithm;

[0055] Judgment module: If there is no abnormal traffic and there are no outliers in the traffic data, prompt that the computer network supports communication, and wake up the VPN monitoring module, the data packet monitoring module, and the detection module;

[0056] VPN monitoring module: During communication, monitor the VPN connection based on the protocol analysis algorithm, and identify whether there are potential abnormalities in the VPN communication;

[0057] Data packet monitoring module: Perform real-time filtering and in-depth detection on the incoming and outgoing data packets of the communication, and identify whether there are threats in the data packets;

[0058] Detection module: Detect whether there are outliers in the VPN connection mode through the Grubbs detection algorithm, and detect whether there are outliers in the data packets through the Grubbs detection algorithm;

[0059] Communication interruption module: If communication anomalies are detected, where the communication anomalies include network abnormal traffic, potential anomalies in VPN communication, data packet threats, or the existence of outliers, directly control the communication interruption;

[0060] Secondary analysis module: If no communication anomaly is detected during monitoring, it acquires traffic data, VPN connections, and the G values calculated from data packets through the Grubbs detection algorithm, performs weighted calculations on multiple G values to generate a communication assignment, and generates corresponding control strategies based on the comparison result between the communication assignment and the gradient anomaly threshold.

[0061] Quality analysis module: After communication ends, it calculates the average communication assignment and communication interruption frequency during the communication process through a polynomial algorithm, analyzes the quality of this communication, and sends the analysis results to the administrator and stores them in the database for subsequent analysis.

[0062] In the above technical solution, the technical effects and advantages provided by the present invention are as follows:

[0063] The present invention analyzes whether the computer network supports communication before communication, and during communication, combines the Grubbs detection algorithm to detect traffic data, VPN connections, and data packets in real time, analyzes whether there are outliers in the traffic data, VPN connections, and data packets, improves the security monitoring effect. When no communication anomaly is detected during monitoring, it acquires traffic data, VPN connections, and the G values calculated from data packets through the Grubbs detection algorithm, performs weighted calculations on multiple G values to generate a communication assignment, and generates corresponding control strategies based on the comparison result between the communication assignment and the gradient anomaly threshold. After communication ends, it calculates the average communication assignment and communication interruption frequency during the communication process through a polynomial algorithm, and analyzes the quality of this communication. This monitoring method can comprehensively analyze the G values of traffic data, VPN connections, and data packets when no communication anomaly is detected, perform secondary analysis on communication security, and further improve the security of communication monitoring. Description of the Drawings

[0064] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.

[0065] Figure 1 It is the method flowchart of the present invention. Detailed Embodiments

[0066] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.

[0067] Example 1: Please refer to Figure 1 As shown, for a computer network communication security monitoring method in this example, the monitoring method includes the following steps:

[0068] Before communication, the monitoring system detects whether there is abnormal traffic in the computer network based on the algorithm of time series pattern recognition, including the following steps:

[0069] Use a network packet capture tool to capture real-time data packets from the network. These data packets include transmitted information, packet size, transmission rate, etc. Arrange the captured data packets in chronological order to form a time series data sequence. Use a time window to divide the time series data into small time periods, such as one time window per second. Extract features from each time window, such as the average size and transmission rate of data packets within that time period. Use a statistics-based method, such as calculating the mean and standard deviation of the data packet size within each time window, to model the normal time series pattern. Compare the real-time traffic data with the modeled normal time series pattern to detect whether there are abnormal situations that do not conform to the normal traffic pattern. For example, it is detected that the data packet size within a certain time window is much higher than normal. When abnormal traffic is detected, the system generates an alarm. For example, the system can send an alert to the administrator to remind them that there may be a network anomaly.

[0070] Identify whether there are outliers in the traffic data through the Grubbs detection algorithm. If there is no abnormal traffic and there are no outliers in the traffic data, the monitoring system prompts that the computer network supports communication. During the communication process, monitor the VPN connection based on the protocol analysis algorithm to identify whether there are potential anomalies in the VPN communication, including the following steps:

[0071] Capture the network traffic data of the VPN communication, including information such as transmitted data packets, protocol types, source and destination IP addresses, etc. Use a network packet capture tool or monitoring device to capture the data packets passing through the VPN connection. Parse the protocol of the captured VPN traffic to identify the protocol used in the communication. Analyze the header information of the data packets to determine the protocol type used, such as IPsec, OpenVPN, etc. Extract protocol features from the VPN communication, including protocol version, encryption algorithm, authentication method, etc. According to the protocol specifications, extract the protocol-related feature information, which will be used for subsequent anomaly detection.

[0072] Establish a protocol behavior model for normal VPN communication for subsequent comparison and anomaly detection. Use known protocol specifications and characteristic information to establish a model of normal VPN communication behavior, including allowed protocol versions, encryption algorithms, authentication methods, etc. Analyze real-time VPN traffic during communication and compare it with the normal protocol behavior model. Check whether the protocol characteristics of the real-time VPN traffic match the established protocol behavior model, compare parameters such as versions and encryption algorithms, and identify situations that do not conform to normal behavior. When potential anomalies are detected in VPN communication, trigger an alarm mechanism to determine whether there are significant differences between the real-time traffic and the normal protocol behavior model. If there are anomalies, trigger an alarm to notify the administrator or relevant personnel.

[0073] Detect whether there are outliers in the VPN connection mode through the Grubbs detection algorithm, and perform real-time filtering and in-depth detection on the incoming and outgoing packets of the communication to identify whether there are threats in the packets, including the following steps:

[0074] Capture the incoming and outgoing packets of the communication and obtain the detailed information of the packets, including source address, destination address, protocol type, data size, etc. Use network packet capture tools or firewall devices to intercept the packets passing through the network device. Perform real-time filtering on the incoming and outgoing packets, and discard or allow specific types of packets according to predefined rules or policies. Use devices such as firewalls or intrusion detection systems (IDS) to perform real-time filtering based on information such as source address, destination address, and protocol. Perform in-depth parsing on the packets that pass through the real-time filtering to further analyze the content and structure of the packets. Use deep packet inspection tools to parse the packets to obtain more detailed information, such as data payload, protocol headers, etc.

[0075] Based on the in-depth parsing, detect whether there are malicious characteristics in the packets, such as malicious code, attack signatures, etc. Use malicious code scanning engines, intrusion detection systems, etc. to perform feature matching on the packets to identify whether they contain known malicious characteristics. Analyze the behavior in the packets to detect whether there are abnormal behaviors, such as a large number of retries, abnormal data transfer rates, etc. Use behavior analysis algorithms to model the temporal behavior of the packets to identify whether it conforms to normal behavior. When threats or abnormal behaviors are detected in the packets, trigger an alarm mechanism. Send an alarm to the Security Information and Event Management system (SIEM), or notify the administrator through other alarm channels.

[0076] Detect whether there are outliers in the packets through the Grubbs detection algorithm. If communication anomalies are monitored, communication anomalies include abnormal network traffic, potential anomalies in VPN communication, packet threats, or the existence of outliers. The monitoring system directly controls the communication interruption, including the following steps:

[0077] The monitoring system detects communication anomalies, which may include abnormal network traffic, potential anomalies in VPN communication, packet threats, or the presence of outliers. Using the aforementioned monitoring methods, such as time-series pattern recognition, protocol analysis, deep packet inspection, etc., trigger the anomaly detection mechanism. Confirm the specific type of the detected communication anomaly, whether it is abnormal network traffic, VPN communication anomaly, packet threat, or outlier. Analyze the specific features and context information that triggered the anomaly detection to confirm the specific type of the anomaly. Based on the anomaly type and security policy, decide whether communication interruption is required, formulate a security policy, define the conditions and urgency for triggering communication interruption so that the system can make an interruption decision automatically or semi-automatically.

[0078] If it is decided to interrupt communication, execute corresponding measures to interrupt the communication to prevent the spread of potential threats. Use means such as firewall rules and router configurations to directly interrupt the connection with the affected communication endpoints. After executing the communication interruption, notify the relevant security teams, administrators, or other relevant personnel. Trigger the alarm notification mechanism to send notifications to pre-defined contacts to alert them of the communication interruption. Record the communication interruption event, generate corresponding reports and logs for subsequent analysis and auditing. Record the detailed information of the communication interruption event into the Security Information and Event Management system (SIEM) for subsequent investigation and analysis. After confirming that the problem is resolved and the communication environment is secure, consider restoring communication. Based on the security assessment and the situation of problem resolution, restore the normal state of the affected communication through corresponding means.

[0079] If no communication anomaly is detected, obtain the G values calculated by the Grubbs detection algorithm for traffic data, VPN connections, and packets, and generate a communication assignment value after weighted calculation of multiple G values. Based on the comparison result between the communication assignment value and the gradient anomaly threshold, generate a corresponding control policy. After the communication ends, calculate the average communication assignment value and communication interruption frequency during the communication process through the polynomial algorithm, analyze the communication quality of this time, and send the analysis results to the administrator and store them in the database for subsequent analysis.

[0080] This application analyzes whether the computer network supports communication before communication, and during communication, combines the Grubbs detection algorithm to detect traffic data, VPN connections, and data packets in real time, analyzes whether there are outliers in the traffic data, VPN connections, and data packets, improves the security monitoring effect. When no communication anomaly is detected, it obtains the G value calculated by the Grubbs detection algorithm for the traffic data, VPN connection, and data packets, and generates a communication assignment after weighted calculation of multiple G values. Based on the comparison result between the communication assignment and the gradient anomaly threshold, a corresponding control strategy is generated. After communication ends, it calculates the average communication assignment and communication interruption frequency during communication through the polynomial algorithm, and then analyzes the communication quality of this time. This monitoring method can comprehensively analyze the G values of traffic data, VPN connections, and data packets when no communication anomaly is detected, and perform a secondary analysis on communication security, further improving the security of communication monitoring.

[0081] Embodiment 2: Before communication, the monitoring system detects whether there is abnormal traffic in the computer network based on the algorithm of time series pattern recognition, and uses the Grubbs detection algorithm to identify whether there are outliers in the traffic data. If there is no abnormal traffic and no outliers in the traffic data, the monitoring system prompts that the computer network supports communication, including the following steps:

[0082] Obtain several data points in the traffic data, and calculate the X value of each data point. The expression is: In the formula, X i represents the X value of the i-th data point, x i represents the traffic value of the i-th data point, x avg represents the average traffic, a represents the standard deviation of traffic data, and the function expression of the standard deviation of traffic data is: In the formula, x i represents the traffic value of the i-th data point, x avg represents the average traffic, i = 1, 2,..., N1, and N1 is the number of data points in the traffic data;

[0083] Then calculate the Grubbs statistic (G value) of the traffic data. The function expression is:

[0084] In the formula, N1 is the number of data points in the traffic data, X i represents the X value of the i-th data point, G1 represents the G value of the traffic data, and max(X i ) represents the maximum X value among the i data points;

[0085] Compare the G value of the obtained traffic data with the preset traffic dispersion threshold. If the G value of the traffic data is greater than the traffic dispersion threshold, analyze that there are outliers in the traffic data and judge that the traffic data is abnormal.

[0086] During the communication process, monitor the VPN connection based on the protocol analysis algorithm, identify whether there are potential anomalies in the VPN communication, and detect whether there are outliers in the VPN connection mode through the Grubbs detection algorithm, including the following steps:

[0087] Obtain a number of data points in the VPN connection and calculate the Y value of each data point. The expression is: In the formula, Y i represents the Y value of the i-th data point, and y i represents the data transmission rate of the i-th data point, and y avg represents the average data transmission rate, b represents the VPN connection standard deviation, and the function expression of the VPN connection standard deviation is: In the formula, y i represents the data transmission rate of the i-th data point, and y avg represents the average data transmission rate, i = 1, 2,..., N2, and N2 is the number of data points in the VPN connection;

[0088] Then calculate the Grubbs statistic (G value) of the VPN connection. The function expression is:

[0089] In the formula, N2 is the number of data points in the VPN connection, Y i represents the Y value of the i-th data point, G2 represents the G value of the VPN connection, and max(Y i ) represents the maximum Y value among the i data points;

[0090] Compare the obtained G value of the VPN connection with the preset VPN dispersion threshold. If the G value of the VPN connection is greater than the VPN dispersion threshold, analyze that there are outliers in the VPN connection and determine that the VPN connection is abnormal.

[0091] Perform real-time filtering and in-depth detection on the incoming and outgoing data packets of the communication, identify whether there are threats in the data packets, and detect whether there are outliers in the data packets through the Grubbs detection algorithm, including the following steps:

[0092] Obtain a number of data points in the data packet and calculate the Z value of each data point. The expression is: In the formula, Z i represents the Z value of the i-th data point, and z i represents the transmission time interval of the i-th data point, and z avg represents the average transmission time interval, c represents the data packet standard deviation, and the function expression of the data packet standard deviation is: In the formula, z i represents the transmission time interval of the i-th data point, and z avgdenotes the average transmission time interval, where i = 1, 2,..., N3, and N3 is the number of data points in the data packet;

[0093] Then calculate the Grubbs statistic (G value) of the data packet. The function expression is:

[0094] In the formula, N3 is the number of data points in the data packet, Z i denotes the Z value of the i-th data point, G3 denotes the G value of the data packet, and max(Z i ) denotes the maximum Z value among the i data points;

[0095] Compare the obtained G value of the data packet with the preset data packet dispersion threshold. If the G value of the data packet is greater than the data packet dispersion threshold, analyze that there are outliers in the data packet and determine that the data packet is abnormal.

[0096] If communication anomalies are detected, where communication anomalies include abnormal network traffic, potential VPN communication anomalies, data packet threats, or the presence of outliers, the monitoring system directly controls the communication interruption. If no communication anomalies are detected, obtain the traffic data, VPN connection, and the G value calculated by the Grubbs detection algorithm for the data packet, and perform weighted calculation on multiple G values to generate a communication assignment. Based on the comparison result between the communication assignment and the gradient anomaly threshold, generate corresponding control strategies, including the following steps:

[0097] During the communication process, regularly obtain the G value of the traffic data, the G value of the VPN connection, and the G value of the data packet;

[0098] Comprehensively perform weighted calculation on the G value of the traffic data, the G value of the VPN connection, and the G value of the data packet to obtain the communication assignment. The expression is: tfz = 0.3 * G1 + 0.4 * G2 + 0.3 * G3. In the formula, tfz is the communication assignment, and G1, G2, and G3 are the G values of the traffic data, the VPN connection, and the data packet respectively.

[0099] After regularly obtaining the communication assignment, compare the communication assignment with the gradient threshold. The gradient threshold includes the first anomaly threshold and the second anomaly threshold. The first anomaly threshold is used to analyze whether there are anomalies during the communication process, and the second anomaly threshold is used to analyze the severity of the communication anomalies;

[0100] If the communication assignment is less than the first anomaly threshold, analyze that there are no anomalies during the communication process;

[0101] If the communication assignment is greater than or equal to the first anomaly threshold, analyze that there are anomalies during the communication process;

[0102] If the communication assignment is greater than or equal to the first anomaly threshold and less than the second anomaly threshold, it is analyzed that there are minor anomalies in the communication process, indicating that the communication can continue. At this time, the monitoring system does not process the communication, sends a warning to the user, and the user can independently choose whether to continue the communication;

[0103] If the communication assignment is greater than or equal to the second anomaly threshold, it is analyzed that there are serious anomalies in the communication process, indicating that continued communication is not supported, and the monitoring system directly disconnects the communication.

[0104] After the communication ends, after calculating the average communication assignment and the communication interruption frequency during the communication process through the polynomial algorithm, the communication quality of this time is analyzed, and the analysis result is sent to the administrator and stored in the database for subsequent analysis, including the following steps:

[0105] After the communication ends, obtain the communication assignments obtained multiple times during the communication process, and calculate the average communication assignment of the multiple communication assignments;

[0106] And obtain the communication interruption frequency during the communication process through the communication monitoring tool, and calculate the quality coefficient by calculating the average communication assignment and the communication interruption frequency through the polynomial algorithm. The expression is:

[0107] Zxs = α * tfz avg + β * zdp; where Zxs is the quality coefficient, tfz avg and zdp are the average communication assignment and the communication interruption frequency respectively, and α and β are the proportionality coefficients of the average communication assignment and the communication interruption frequency respectively, and both α and β are greater than 0;

[0108] Compare the quality coefficient with the preset quality threshold. If the quality coefficient is less than or equal to the quality threshold, it is analyzed that the communication quality is qualified. If the quality coefficient is greater than the quality threshold, it is analyzed that the communication quality is unqualified. Send the analysis result to the administrator and store it in the database for subsequent analysis. When the analysis shows that the quality is unqualified, the administrator needs to promptly maintain the computer and the computer network.

[0109] Embodiment 3: The computer network communication security monitoring system described in this embodiment includes a traffic monitoring module, a judgment module, a VPN monitoring module, a data packet monitoring module, a detection module, a communication interruption module, a secondary analysis module, and a quality analysis module;

[0110] Traffic monitoring module: Before the communication, detect whether there is abnormal traffic in the computer network based on the algorithm of time series pattern recognition, and identify whether there are outliers in the traffic data through the Grubbs detection algorithm. The detection result and the recognition result are sent to the judgment module;

[0111] Judgment module: If there is no abnormal traffic and there are no outliers in the traffic data, it prompts that the computer network supports communication and wakes up the VPN monitoring module, the data packet monitoring module, and the detection module;

[0112] VPN monitoring module: During the communication process, it monitors the VPN connection based on the protocol analysis algorithm, identifies whether there are potential abnormalities in the VPN communication, and sends the identification results to the communication interruption module and the secondary analysis module;

[0113] Data packet monitoring module: It performs real-time filtering and in-depth detection on the data packets incoming and outgoing from the communication, identifies whether there are threats in the data packets, and sends the identification results to the communication interruption module and the secondary analysis module;

[0114] Detection module: It detects whether there are outliers in the VPN connection mode through the Grubbs detection algorithm, and detects whether there are outliers in the data packets through the Grubbs detection algorithm, and sends the detection results to the communication interruption module and the secondary analysis module;

[0115] Communication interruption module: If communication abnormalities are detected, the communication abnormalities include network abnormal traffic, potential abnormalities in VPN communication, data packet threats, or the existence of outliers, it directly controls the communication interruption;

[0116] Secondary analysis module: If no communication abnormalities are detected, it obtains the traffic data, the VPN connection, and the G values calculated by the Grubbs detection algorithm for the data packets, performs weighted calculation on multiple G values to generate a communication assignment value, generates corresponding control strategies based on the comparison result between the communication assignment value and the gradient abnormality threshold, and sends the communication assignment value to the quality analysis module;

[0117] Quality analysis module: After the communication ends, it calculates the average communication assignment value and the communication interruption frequency during the communication process through the polynomial algorithm, analyzes the quality of this communication, and sends the analysis results to the administrator and the database for storage for subsequent analysis.

[0118] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0119] In the description of this specification, the descriptions referring to terms such as "one embodiment", "example", "specific example", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0120] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to only the specific embodiments. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.

Claims

1. A computer network communication security monitoring method, characterized in that: The monitoring method includes the following steps: Before communication, the monitoring system detects whether there is abnormal traffic in the computer network based on the algorithm of time series pattern recognition, and identifies whether there are outliers in the traffic data through the Grubbs detection algorithm. If there is no abnormal traffic and no outliers in the traffic data, the monitoring system prompts that the computer network supports communication; During communication, the VPN connection is monitored based on the protocol analysis algorithm to identify whether there are potential anomalies in the VPN communication, and the Grubbs detection algorithm is used to detect whether there are outliers in the VPN connection mode; The incoming and outgoing data packets of the communication are filtered and deeply detected in real time to identify whether there are threats in the data packets, and the Grubbs detection algorithm is used to detect whether there are outliers in the data packets; If communication anomalies are detected, the monitoring system directly controls the communication interruption. If no communication anomalies are detected, the G values calculated by the Grubbs detection algorithm for the traffic data, VPN connection, and data packets are obtained, and the multiple G values are weighted and calculated to generate a communication assignment. Based on the comparison result between the communication assignment and the gradient anomaly threshold, corresponding control strategies are generated; After the communication ends, the average communication assignment and communication interruption frequency during the communication process are calculated through the polynomial algorithm, and the communication quality is analyzed. The analysis result is sent to the administrator and stored in the database for subsequent analysis.

2. The computer network communication security monitoring method according to claim 1, characterized in that: The communication anomalies include network abnormal traffic, potential anomalies in VPN communication, data packet threats, or outliers.

3. The computer network communication security monitoring method according to claim 2, characterized in that: Identifying whether there are outliers in the traffic data through the Grubbs detection algorithm includes the following steps: Obtain several data points in the traffic data and calculate the X value of each data point. The expression is: In the formula, X i represents the X value of the i-th data point, and x i represents the traffic value of the i-th data point, and x avg represents the average traffic, and a represents the standard deviation of the traffic data; Calculating the Grubbs statistic of the traffic data, and the function expression is: Wherein, N1 is the number of data points in the flow rate data, and X i represents the X value of the i-th data point, G1 represents the G value of the flow rate data, and max(X i ) represents the maximum X value selected from the i data points; Comparing the G value of the obtained traffic data with the preset traffic dispersion threshold. If the G value of the traffic data is greater than the traffic dispersion threshold, it is analyzed that there are outliers in the traffic data, and it is determined that the traffic data is abnormal; Detecting whether there are outliers in the VPN connection mode through the Grubbs detection algorithm includes the following steps: Obtain several data points in the VPN connection and calculate the Y value of each data point. The expression is: In the formula, Y i represents the Y value of the i-th data point, and y i represents the data transfer rate of the i-th data point, and y avg represents the average data transfer rate, and b represents the VPN connection standard deviation; Calculating the Grubbs statistic of the VPN connection, and the function expression is: where N2 is the number of data points in the VPN connection, and Y i represents the Y value of the i-th data point, G2 represents the G value of the VPN connection, and max(Y i ) represents the maximum Y value among the i data points; Comparing the G value of the obtained VPN connection with the preset VPN dispersion threshold. If the G value of the VPN connection is greater than the VPN dispersion threshold, it is analyzed that there are outliers in the VPN connection, and it is determined that the VPN connection is abnormal; Detecting whether there are outliers in the data packets through the Grubbs detection algorithm includes the following steps: Obtain several data points in the data packet and calculate the Z value of each data point. The expression is: In the formula, Z i represents the Z value of the i-th data point, z i represents the transmission time interval of the i-th data point, z avg represents the average transmission time interval, and c represents the standard deviation of the data packet; Calculating the Grubbs statistic of the data packet, and the function expression is: In the formula, N3 is the number of data points in the data packet, and Z i represents the Z value of the i-th data point, G3 represents the G value of the data packet, and max(Z i ) represents the maximum Z value among the i data points; Comparing the G value of the obtained data packet with the preset data packet dispersion threshold. If the G value of the data packet is greater than the data packet dispersion threshold, it is analyzed that there are outliers in the data packet, and it is determined that the data packet is abnormal.

4. A computer network communication security monitoring method according to claim 3, characterized in that: If no communication anomalies are detected, the G values calculated by the Grubbs detection algorithm for the traffic data, VPN connection, and data packets are obtained, and the multiple G values are weighted and calculated to generate a communication assignment, including the following steps: During communication, the G value of the traffic data, the G value of the VPN connection, and the G value of the data packet are obtained regularly; The communication assignment is obtained by comprehensively weighted calculation of the G value of traffic data, the G value of VPN connection, and the G value of data packets. The expression is: tfz = ω1 * G1 + ω2 * G2 + ω3 * G3, where tfz is the communication assignment, G1, G2, and G3 are the G values of traffic data, the G value of VPN connection, and the G value of data packets respectively, ω1, ω2, and ω3 are the weight coefficients of the G values of traffic data, the G value of VPN connection, and the G value of data packets respectively, and ω1 + ω2 + ω3 = 1, ω2 > ω1 = ω3.

5. A computer network communication security monitoring method according to claim 4, characterized in that: Based on the comparison result between the communication assignment and the gradient anomaly threshold, the corresponding control strategy is generated, including the following steps: After regularly obtaining the communication assignment, compare the communication assignment with the gradient thresholds. The gradient thresholds include the first anomaly threshold and the second anomaly threshold. The first anomaly threshold is used to analyze whether there is an anomaly during the communication process, and the second anomaly threshold is used to analyze the severity of the communication anomaly; If the communication assignment is less than the first anomaly threshold, it is analyzed that there is no anomaly during the communication process; If the communication assignment is greater than or equal to the first anomaly threshold, it is analyzed that there is an anomaly during the communication process; If the communication assignment is greater than or equal to the first anomaly threshold and less than the second anomaly threshold, it is analyzed that there is a minor anomaly during the communication process, indicating that the communication can continue. At this time, the monitoring system does not process the communication, sends a warning to the user, and the user can independently choose whether to continue the communication; If the communication assignment is greater than or equal to the second anomaly threshold, it is analyzed that there is a serious anomaly during the communication process, indicating that continued communication is not supported, and the monitoring system directly disconnects the communication.

6. A computer network communication security monitoring method according to claim 5, characterized in that: After the communication ends, the average communication assignment and the communication interruption frequency during the communication process are calculated through the polynomial algorithm, and then the communication quality of this time is analyzed, including the following steps: After the communication ends, obtain the communication assignments obtained multiple times during the communication process, and calculate the average communication assignment of the multiple communication assignments; And obtain the communication interruption frequency during the communication process through the communication monitoring tool. The average communication assignment and the communication interruption frequency are calculated through the polynomial algorithm to obtain the quality coefficient. The expression is: Zxs = α * tfz avg + β * zdp; where Zxs is the mass coefficient, tfz avg , zdp are the average communication assignment and the communication interruption frequency respectively, α, β are the proportionality coefficients of the average communication assignment and the communication interruption frequency respectively, and both α and β are greater than 0; Compare the quality coefficient with the preset quality threshold. If the quality coefficient is less than or equal to the quality threshold, it is analyzed that the communication quality is qualified. If the quality coefficient is greater than the quality threshold, it is analyzed that the communication quality is unqualified, and the analysis result is sent to the administrator and stored in the database for subsequent analysis.

7. A computer network communication security monitoring method according to claim 6, characterized in that: Before the monitoring system conducts communication, it detects whether there is abnormal traffic in the computer network based on the algorithm of time series pattern recognition, including the following steps: Use the network packet capture tool to capture real-time data packets from the network. The data packets include the transmitted information, the packet size, and the transmission rate. Arrange the captured data packets in chronological order to form a time series data sequence; Use the time window to divide the time series data into small time periods, extract features from each time window, calculate the mean and standard deviation of the packet size within each time window to model the time series pattern, and compare the real-time traffic data with the modeled time series pattern to detect whether there is an abnormal situation that does not conform to the normal traffic pattern.

8. A computer network communication security monitoring method according to claim 7, characterized in that: During communication, monitor the VPN connection based on the protocol analysis algorithm to identify potential anomalies in VPN communication, including the following steps: Capture the network traffic data of VPN communication, including the transmitted data packets, protocol types, source and destination IP address information. Use a network packet capture tool or monitoring device to capture the data packets passing through the VPN connection, and perform protocol parsing on the captured VPN traffic to identify the protocols used in the communication; Analyze the header information of the data packets to determine the protocol types used, extract the protocol features from the VPN communication, and use the known protocol specifications and feature information to establish a model of VPN communication behavior, including the allowed protocol versions, encryption algorithms, and authentication methods; During communication, analyze the real-time VPN traffic and compare it with the model of VPN communication behavior to check whether the protocol features of the real-time VPN traffic match the established protocol behavior model and identify situations that do not conform to normal behavior.

9. A computer network communication security monitoring method according to claim 8, characterized in that: Perform real-time filtering and in-depth detection on the data packets incoming and outgoing from the communication to identify whether there are threats in the data packets, including the following steps: Capture the data packets incoming and outgoing from the communication and obtain the detailed information of the data packets, including the source address, destination address, protocol type, and data size. Use a network packet capture tool or firewall device to intercept the data packets passing through the network device; Use a firewall or intrusion detection system to perform real-time filtering on the incoming and outgoing data packets based on the source address, destination address, and protocol information, and use a deep packet detection tool to perform in-depth parsing on the data packets passing through the real-time filtering, and further analyze the content and structure of the data packets. The content and structure include the data payload and protocol header; Use a malicious code scanning engine and intrusion detection system to detect whether there are malicious features in the data packets, including malicious code and attack signatures, perform feature matching on the data packets to identify whether they contain known malicious features, and analyze the behavior in the data packets to detect whether there are abnormal behaviors.

10. A computer network communication security monitoring system for implementing the monitoring method described in any one of claims 1-9, characterized in that: Including a traffic monitoring module, a judgment module, a VPN monitoring module, a data packet monitoring module, a detection module, a communication interruption module, a secondary analysis module, and a quality analysis module; Traffic monitoring module: Before communication, detect whether there is abnormal traffic in the computer network based on the algorithm of time series pattern recognition, and identify whether there are outliers in the traffic data through the Grubbs detection algorithm; Judgment module: If there is no abnormal traffic and there are no outliers in the traffic data, prompt that the computer network supports communication and wake up the VPN monitoring module, the data packet monitoring module, and the detection module; VPN monitoring module: During communication, monitor the VPN connection based on the protocol analysis algorithm to identify potential anomalies in VPN communication; Data packet monitoring module: Perform real-time filtering and in-depth detection on the data packets incoming and outgoing from the communication to identify whether there are threats in the data packets; Detection module: Detect whether there are outliers in the VPN connection mode through the Grubbs detection algorithm, and detect whether there are outliers in the data packets through the Grubbs detection algorithm; Communication interruption module: If communication anomalies are detected, including abnormal network traffic, potential VPN communication anomalies, packet threats, or outliers, directly control communication interruption; Secondary analysis module: If no communication anomalies are detected, obtain the traffic data, VPN connections, and G values calculated by the Grubbs detection algorithm for the packets, perform weighted calculations on multiple G values to generate a communication assignment, and generate corresponding control strategies based on the comparison result between the communication assignment and the gradient anomaly threshold; Quality analysis module: After communication ends, calculate the average communication assignment and communication interruption frequency during the communication process through a polynomial algorithm, analyze the communication quality of this time, and send the analysis results to the administrator and store them in the database for subsequent analysis.

Citation Information

Patent Citations

  • A user account abnormity detection method and device based on time sequence characteristics

    CN109818942A

  • Industrial control system security threat assessment method, device and system

    CN112184091A